|
|
|
|
Bonjour, j'ai choppé un virus hier soir en voulant télécharger un logiciel (web creator) sur un site étranger (site russe). lors de l'installation, avast m'a détecté un virus, je l'ai donc supprimé mais j'ai quand même installé le logiciel (chose que je ne fais pas d'habitude mais la !!!). tout marchait très bien hier soir, mais ce matin lorsque j'ai rallumé le pc, avast détecte le virus Win32:Trojan-gen {other} mais n'arrive pas à le supprimer.
depuis, plein de page d'installation du logiciel s'ouvre.
aidez moi s'il vous plais merci.
voici le rapport hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:04:40, on 25/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Windows\system32\Updater.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\VM_STI.EXE
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-K66C4.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-5JSBT.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-UP2IN.tmp\wpm.tmp
C:\Windows\System32\mobsync.exe
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-35M75.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\is-O1G4G.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Program Files\GigaTribe\gigatribe.exe
C:\Users\bob\AppData\Local\Temp\is-DF9BL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-IPJD7.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-9L935.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-84RB2.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-MI9EU.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-OD3FL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-UGI9H.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-234AM.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-0EEAH.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6GC49.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-LTUGD.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-TKT2M.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-GNONR.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-TJKRD.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-NNR28.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-1LKT1.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-R2K3K.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-62FUN.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-4MAEL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-D7793.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6HRVM.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-D6OHL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-28BN5.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-E082B.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-JTGS4.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-K93CG.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-I3CC7.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-4LJP5.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-A1RIP.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-J8ED9.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-BII3O.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-RH5G1.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-B3047.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-QGIGB.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-CB653.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-EL3DT.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-5IA3V.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-J3S7L.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-FNE73.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-IMKO3.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6UMDC.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-5ELD7.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-IQ1GP.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-IED0T.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-4DLLJ.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-FR3OL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-NN42P.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6DFEL.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-2OTLU.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-NSRBE.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-BJS0J.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6QTNI.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-1ABMD.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-49I7D.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-DV8A1.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-M81C9.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6B9OH.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-QLLTP.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-4QF8G.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-P75TO.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-L1J4S.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-QP2MF.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-R0PMN.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-3G5H0.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-RE9V5.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-LGV5R.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-59P9V.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-6SFIG.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-O6273.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-N0S70.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-LCIUP.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-ENKD9.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-VA01K.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-3V0R0.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-670BO.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-MPC03.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-7BNKE.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-UQOQG.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-HDCVB.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-94ULF.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-5VG4R.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-LSIH0.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-UBHJC.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-G4K7V.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-H3I8F.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-IQ415.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-7HUFA.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-OLLS7.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-49TGK.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-US0NQ.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-1V0PE.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Windows\System32\vlcc.exe
C:\Windows\System32\vlcc.exe
C:\Users\bob\AppData\Local\Temp\is-P9B01.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\wpm.exe
C:\Users\bob\AppData\Local\Temp\is-EUV6F.tmp\wpm.tmp
C:\Users\bob\AppData\Local\Temp\is-K0ONU.tmp\wpm.tmp
C:\Windows\system32\SearchFilterHost.exe
C:\Users\bob\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [tutute] C:\Windows\system32\vlcc.exe
O4 - HKLM\..\Run: [BigDogPath] C:\Windows\VM_STI.EXE V-Gear TalkCam 1.1
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Windows Update] "C:\Windows\system32\Updater.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\EA Games\Need for Speed Undercover\PB\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
End of file - 16906 bytesConfiguration: Windows Vista
Firefox 3.0.9
Bonjour, tu vas faire un nettoyage avec ccleaner et les réglages donnés et puis tu passeras malwarebytes tu posteras le rapport suivi d'un nouveau hijackthis , Merci
|
Ok merci jacques.gache, je suis en train de le faire et je te donne les résultats après.
|
Voici le rapport malwarebyte's:
|
Peux tu faire lop S&D option 1 et 2 tu postes les rapports merci
|
Voila le rapport:
|
Bon ça a l'aire pas mal tout cela mais bon tu ma poster deux fois le même l'option 2 , tu as vu la collection de trucs avec les craks il faut pas être surpris d'avoir des problèmes http://forum.malekal.com/viewtopic.php?f=33&t=893
|
Merci jacques.gache. perso, je ne vais jamais sur des sites de crack, je prends toujours mes logiciels sur des sites sûres (lorsqu'ils sont en version gratuite), ou sur des sites sûres mais pas vraiment légal (lorsqu'ils sont en version payante). celui la je l'ai chopé en voulant tester "web creator" qui provient d'un site de DL russe. mais je crois que j'ai compris la leçon, je ne DL plus sur ce site des logiciels.
|
Tu me remetteras un dernier hijackthis et je te donnerais la suite on reprendra demain ou après demain scelon ta disponibilité bon courrage pour le boulot @+
--------------------\\ Cracks & Keygens .. C:\Users\bob\AppData\Roaming\uTorrent\crack tomtom+ photos tuto.rar.torrent C:\Users\bob\AppData\Roaming\uTorrent\Poker Academy Pro 2.5 [English & French] + crack.torrent C:\Users\bob\AppData\Roaming\uTorrent\WindowsR Genuine Advantage Validation Crack III.torrent C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Dreamweaver8-fr C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Dreamweaver8-fr.rar C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Fireworks8-fr.rar C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Flash8-fr.rar C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\keygen C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\keygen.rar C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Dreamweaver8-fr\Dreamweaver8-fr.exe C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\keygen\keygen.exe C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Dreamweaver8-fr C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Fireworks8-fr.rar C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Flash8-fr C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\keygen C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Dreamweaver8-fr\Dreamweaver8-fr.exe C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Flash8-fr\Flash8-fr.exe C:\Users\bob\Downloads\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\Macromedia.Dreamweaver.v8.0+Flash.v8+Fireworks.v8+Keygen_PC-FR-VF\keygen\keygen.exe C:\Users\bob\Videos\crack tomtom+ photos tuto.rar C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack C:\Users\bob\Videos\WindowsR Genuine Advantage Validation Crack III C:\Users\bob\Videos\alcool_120ø\crack.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\DeviceID.txt C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Meta.txt C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\RunMeforAllAutomatic.cmd C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\RunMeforDCT.cmd C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\RunMeforMetaKey.cmd C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\keygen6.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\meta.txt C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\tt7_keygen.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\tt7_metacheck.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\tt8_keygen.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\tt8_mapcheck.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\Progs\tt8_mapcheck2.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\Compact.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\cygwin1.dll C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\Extract.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\gzip.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\Patcher.exe C:\Users\bob\Videos\France_v815_2003\Easyusetools_for Keygen_Mapcheck_Metacheck_ttsystempatcher\ttsystem_Patcher\RunMe.bat C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\EasyuseToolforV6MapsKeygen C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\EasyuseToolforV6MapsKeygen\DeviceID.txt C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\EasyuseToolforV6MapsKeygen\keygen.exe C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\EasyuseToolforV6MapsKeygen\Readme.txt C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\EasyuseToolforV6MapsKeygen\RunMeforCode.cmd C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\In_Case_of_Emergency\tt7_keygen.exe C:\Users\bob\Videos\France_v815_2003\In_Case_of_Emergency\In_Case_of_Emergency\tt8_keygen.exe C:\Users\bob\Videos\Lavalys EVEREST Ultimate Edition v4 60 1500.by liliu\keygen C:\Users\bob\Videos\Lavalys EVEREST Ultimate Edition v4 60 1500.by liliu\keygen\keygen.exe C:\Users\bob\Videos\Logiciels Slysoft (CloneCD, CloneDVD, CloneDVD Mobile, AnyDVD)\Crack.exe C:\Users\bob\Videos\Pack_Carte_Europe +cerise+Navcore_8.060.9425\Easyusetools_for Keygen.rar C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\PokerAcademyPro2-setup.exe C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\README 1ST.TXT C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack\A.class C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack\aquila.jar C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack\exe4jlib.jar C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack\meerkatRun.jar C:\Users\bob\Videos\Poker Academy Pro 2.5 [English & French] + crack\crack\PokerAcademyPro.exe C:\Users\bob\Videos\Virtual Plastic Surgery Software 1.0.0.1484\Virtual Plastic Surgery Software 1.0.0.1484\Crack C:\Users\bob\Videos\Virtual Plastic Surgery Software 1.0.0.1484\Virtual Plastic Surgery Software 1.0.0.1484\Crack\file_id.diz C:\Users\bob\Videos\Virtual Plastic Surgery Software 1.0.0.1484\Virtual Plastic Surgery Software 1.0.0.1484\Crack\inv.nfo C:\Users\bob\Videos\Virtual Plastic Surgery Software 1.0.0.1484\Virtual Plastic Surgery Software 1.0.0.1484\Crack\vpss.exe C:\Users\bob\Videos\WindowsR Genuine Advantage Validation Crack III\WindowsR Genuine Advantage Validation Crack III.exeAttention !! la surmultiplication de logiciels de sécurité ne protège pas mieux voire peut engendrer des conflits et des plantages. " mais chacun reste maître de son PC " |
Salut. voila je te poste le dernier résultat hijackthis. en ce qui concerne les cracks, ils sont dans les fichiers que je télécharge. c'est pas moi qui vais les chercher sur des sites de cracks. enfin bref, sa m'apprendra.
|
Bon 2 chose tu vas arrêter le service symantec " norton " et spybot qui n'est plus installer sur ton pc
|
Voila le rapport avec otmovit:
|
Ok vu le résultat de virus total tu passes drweb et tu poste le rapport , et un nouveau hijackthis merci
|
Salut. voici ce que tu m'a demandé. en espérant avoir réussi a faire tout correctement.
|
Bonjour, ok c'est bon pour moi tu fais ce qui suit et si plus de problème tu mettras ton sujet en résolu au niveau de ton premier message , merci
|
Ok et merci pour tout.
|