Bonjour,
Voici le rapport de Toolbar:
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz )
BIOS : Default System BIOS
USER : loquacissima ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Activated)
C:\ (Local Disk) - NTFS - Total:223 Go (Free:106 Go)
D:\ (Local Disk) - NTFS - Total:9 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 16/08/2009| 0:03 )
[ UAC => 1 ]
-----------\\ SUPPRESSION
Supprime! - [Service] ASKService
Supprime! - [Service] ASKUpgrade
Supprime! - C:\Program Files\AskBarDis\bar
Supprime! - C:\Program Files\AskBarDis\unins000.dat
Supprime! - C:\Program Files\AskBarDis\unins000.exe
Supprime! - C:\Program Files\AskBarDis
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://ie.redirect.hp.com/..."
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR"
"Search Bar"="http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR"
"Url"="http://go.microsoft.com/fwlink/?LinkId=75720"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://ie.redirect.hp.com/..."
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
--------------------\\ Recherche d'autres infections
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{41761A96-69E5-4AB7-8C08-0D457FD20FDA}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
DhcpNameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{41761A96-69E5-4AB7-8C08-0D457FD20FDA}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
DhcpNameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{41761A96-69E5-4AB7-8C08-0D457FD20FDA}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
NameServer REG_SZ 85.255.112.83,85.255.112.20
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{F51B00EA-55E8-4693-B6C9-A5DA57D81264}]
DhcpNameServer REG_SZ 85.255.112.83,85.255.112.20
[b]==> WAREOUT <==/b
--------------------\\ Cracks & Keygens ..
C:\Users\LOQUAC~1\Documents\CambridgeSoft-fichier installation\ChemOffice\keygen.exe
C:\Users\LOQUAC~1\Music\musique\ABBA-_The_Definitive_Collection_-_by_baleog3\The Definitive Collection Disc 2\12 The Visitors (Crackin' Up).mp3
[ UAC => 1 ]
Ensuite pour Malwarebytes Anti-Malwares, le lien que vous m'avait donné ne marchait pas, j'ai cherché et trouvé tout de meme le programme Malwarebytes Anti-Malwares 1.4. Cependant, une erreur se produit lors de la mise à jour, je pense que cela vient du trojan, j'ai le meme probleme avec mon spybot. J'ai tout de meme lancer l'analyse.... 15 eléments infectés donc supprimés
Voici le rapport:
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ESQULserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{41761a96-69e5-4ab7-8c08-0d457fd20fda}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{41761a96-69e5-4ab7-8c08-0d457fd20fda}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{41761a96-69e5-4ab7-8c08-0d457fd20fda}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{f51b00ea-55e8-4693-b6c9-a5da57d81264}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.83,85.255.112.20 -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.