| Répondre à boulepate62 | Salut boulepate
voici le rapport demandé :
Deckard's System Scanner v20070426.43
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professionnel (build 2600) SP 2.0
Architecture: X86; Language: French
CPU 0: AMD Athlon(tm) XP 1900+
Percentage of Memory in Use: 53%
Physical Memory (total/avail): 511.48 MiB / 239.31 MiB
Pagefile Memory (total/avail): 1249.94 MiB / 1045.46 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1975.53 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 29.29 GiB total, 15.34 GiB free.
D: is Fixed (NTFS) - 45.23 GiB total, 7.52 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FirstRunDisabled is set.
FW: Sunbelt Personal Firewall v4.5.916 T (Sunbelt) [COLOR=RED]Disabled[/COLOR]
AV: Kaspersky Anti-Virus v6.0.2.621 () [COLOR=RED]Disabled[/COLOR]
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=D:\Documents and Settings\All Users
APPDATA=D:\Documents and Settings\CastingSurf.com\Application Data
CLASSPATH=D:\Program Files\QuickTime\QTSystem\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=D:\Program Files\Fichiers communs
COMPUTERNAME=DARCY-BA2B2F36F
ComSpec=D:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=D:
HOMEPATH=\Documents and Settings\CastingSurf.com
LOGONSERVER=\\DARCY-BA2B2F36F
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=D:\WINDOWS\system32;D:\WINDOWS;D:\WINDOWS\system32\WBEM;D:\Program Files\QuickTime\QTSystem\;D:\Program Files\Fichiers communs\Ulead Systems\MPEG;D:\Program Files\Fichiers communs\Ahead\Lib\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 6 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0602
ProgramFiles=D:\Program Files
PROMPT=$P$G
QTJAVA=D:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=D:
SystemRoot=D:\WINDOWS
TEMP=D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp
TMP=D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp
USERDOMAIN=DARCY-BA2B2F36F
USERNAME=CastingSurf.com
USERPROFILE=D:\Documents and Settings\CastingSurf.com
windir=D:\WINDOWS
-- User Profiles ---------------------------------------------------------------
CastingSurf.com [I](admin)[/I]
Administrateur [I](admin)[/I]
-- Add/Remove Programs ---------------------------------------------------------
-- End of Deckard's System Scanner: finished at 2007-05-22 at 20:06:44 ---------
Ok Répondre à alexdarcy |
| Boulepate j'ai oublié de te dire qu'au démarage de Windows j'ai toujours cette petite fenetre "dialog" qui s'ouvre furtivement. Est-ce un virus qui ouvre cette fenetre ? Pourtant et d'après tous les anti-virus et anti-spy je ne suis plus infecté ..
Ok Répondre à alexdarcy | Le rapport Combo est incomplet, tu devrais avoir entre deux et trois rapports ;-)
c'est en forgeant que l'on devient forgeron !
** site perso pour forger, dans mon profil ** Répondre à boulepate62 |
| Oui je me disais qu'il devait avoir erreur lol !
Voici le second :
Deckard's System Scanner v20070426.43
Run by CastingSurf.com on 2007-05-22 at 20:03:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
6: 2007-05-22 18:03:49 UTC - RP6 - Deckard's System Scanner Restore Point
5: 2007-05-20 19:43:43 UTC - RP5 - Point de vérification système
4: 2007-05-18 22:58:49 UTC - RP4 - Point de vérification système
3: 2007-05-17 22:56:24 UTC - RP3 - Point de vérification système
2: 2007-05-16 22:52:31 UTC - RP2 - Point de vérification système
-- First Restore Point --
1: 2007-05-15 00:31:48 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-05-22 20:06:19
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.0.2900.2180)
Running processes:
D:\WINDOWS\system32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe
D:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Documents and Settings\CastingSurf.com\Bureau\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [MaxtorOneTouch] D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] D:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma.lnk = D:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MsMsgs.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MsMsgs.EXE
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/...
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_01) - http://java.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: klogon - D:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\system32\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Service de la passerelle de la couche Application (ALG) - Unknown owner - D:\WINDOWS\System32\alg.exe
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - D:\WINDOWS\system32\aspi165610.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Microsoft Corp., Veritas Software - D:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: Macromedia Licensing Service - Unknown owner - "D:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe"
O23 - Service: NBService - Unknown owner - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - D:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - D:\WINDOWS\system32\netdde.exe
O23 - Service: NMIndexingService - Nero AG - "D:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe"
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - "D:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
-- HijackThis Fixed Entries (D:\Documents and Settings\CastingSurf.com\Bureau\abc\backups\) --------------------------------------------------------------------------------
backup-20070522-195909-948 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
backup-20070522-195912-807 O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (Installer Class) - http://www.nanoscan.com/as/v1/cabs/ascinstie.cab
backup-20070522-195913-146 O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
backup-20070522-195914-616 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
backup-20070522-195914-854 O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
backup-20070522-195916-328 O22 - SharedTaskScheduler: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - (no file)
backup-20070522-195917-410 O22 - SharedTaskScheduler: {03413bf7-e34c-445b-bfc0-a2b127255871} - incestuously - (no file)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 oreans32 - d:\windows\system32\drivers\oreans32.sys
R1 PCLEPCI - d:\windows\system32\drivers\pclepci.sys <Not Verified; Pinnacle Systems GmbH; PCLEPCI>
R3 ASAPIW2k - d:\windows\system32\drivers\asapiw2k.sys <Not Verified; Pinnacle Systems GmbH; asapi>
R3 pcouffin (VSO Software pcouffin) - d:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S3 CO_Mon - d:\windows\system32\drivers\co_mon.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R3 NMIndexingService - "d:\program files\fichiers communs\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>
S3 NBService - d:\program files\nero\nero 7\nero backitup\nbservice.exe
S4 ALG (Service de la passerelle de la couche Application) - d:\windows\system32\alg.exe (file missing)
S4 aspi113210 (Microsoft ASPI Manager) - d:\windows\system32\aspi165610.exe (file missing)
S4 NetDDE (DDE réseau) - d:\windows\system32\netdde.exe (file missing)
S4 NetDDEdsdm (DSDM DDE réseau) - d:\windows\system32\netdde.exe (file missing)
-- Files created between 2007-04-22 and 2007-05-22 -----------------------------
2007-05-18 22:05:35 0 dr-h----- D:\Documents and Settings\CastingSurf.com\Recent
2007-05-16 19:07:37 0 d-------- D:\Documents and Settings\CastingSurf.com\DoctorWeb
2007-05-16 01:30:05 0 d-------- D:\VundoFix Backups
2007-05-15 01:12:11 0 d-------- D:\WINDOWS\system32\Panda Software
2007-05-15 01:03:19 0 d-------- D:\WINDOWS\system32\ActiveScan
2007-05-14 16:40:37 0 d-------- D:\Program Files\Sunbelt Software
2007-05-14 00:31:57 82258 --a------ D:\WINDOWS\system32\drivers\klin.dat
2007-05-14 00:31:57 82258 --a------ D:\WINDOWS\system32\drivers\klick.dat
2007-05-14 00:31:09 0 d-------- D:\Program Files\Kaspersky Lab
2007-05-14 00:31:09 0 d-------- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-05-14 00:31:05 83488 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.dat
2007-05-14 00:31:05 4564256 --ahs---- D:\WINDOWS\system32\drivers\fidbox.dat
2007-05-12 12:23:18 876547 --a------ D:\WINDOWS\system32\SmitfraudFix.exe
2007-05-10 19:02:38 0 d-------- D:\Program Files\VerifMail
2007-05-10 02:48:15 0 d-------- D:\WINDOWS\system32\Kaspersky Lab
2007-05-09 22:14:17 0 d-------- D:\Program Files\Hijackthis Version Française
2007-05-09 22:06:53 0 d-------- D:\Documents and Settings\All Users\Application Data\Avg7
2007-05-09 21:15:03 0 dr-h----- D:\$VAULT$.AVG
-- Find3M Report ---------------------------------------------------------------
2007-05-15 01:48:45 0 d-------- D:\Program Files\Fichiers communs\Symantec Shared
2007-05-15 00:51:40 0 d-------- D:\Program Files\The Cleaner
2007-05-14 00:20:48 0 d-------- D:\Program Files\Fichiers communs
2007-05-12 12:40:59 0 d-------- D:\Documents and Settings\CastingSurf.com\Application Data\AVS Video Converter
2007-05-11 03:51:45 0 d-------- D:\Program Files\Ludiclub
2007-04-27 20:31:07 0 d-------- D:\Program Files\eRightSoft
2007-04-22 03:09:13 0 d-------- D:\Documents and Settings\CastingSurf.com\Application Data\Symantec
2007-04-17 20:05:29 0 d-------- D:\Documents and Settings\CastingSurf.com\Application Data\Sun
2007-04-17 19:42:54 0 d-------- D:\Program Files\Java
2007-04-17 19:40:25 0 d-------- D:\Program Files\Fichiers communs\Java
2007-04-03 22:11:56 0 d-------- D:\Program Files\DivX
2007-04-03 07:37:50 0 d-------- D:\Program Files\MediaCoder
2007-04-03 06:44:40 0 d-------- D:\Documents and Settings\CastingSurf.com\Application Data\DivX
2007-03-27 20:55:45 0 d-------- D:\Program Files\Pinnacle
2007-03-27 20:52:41 95 --a------ D:\AUTOEXEC.BAT
2007-03-27 20:48:55 0 d--h----- D:\Program Files\InstallShield Installation Information
2007-03-26 02:40:39 0 d-------- D:\Program Files\IKEA HomePlanner
2007-03-25 21:22:11 367658 --a----c- D:\WINDOWS\system32\perfh00C.dat
2007-03-25 21:22:11 48616 --a----c- D:\WINDOWS\system32\perfc00C.dat
2007-03-23 06:29:01 0 d-------- D:\Program Files\Fichiers communs\Wise Installation Wizard
2007-03-09 19:52:52 200768 --a------ D:\WINDOWS\system32\klogon.dll <Not Verified; Kaspersky Lab; Kaspersky Anti-Virus>
-- Registry Dump ---------------------------------------------------------------
-- End of Deckard's System Scanner: finished at 2007-05-22 at 20:06:44 ---------
Ok Répondre à alexdarcy |
| ... et celui ci qui fait 3 lol :
Directories/Files moved to D:\Deckard\System Scanner\backup
2007-05-19 05:07:50 0 d-------- D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\hsperfdata_CastingSurf.com
2007-01-20 00:54:07 17929072 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\Install_Messenger.exe <Verified; Microsoft Corporation; Messenger>
2007-05-19 05:08:05 832 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\java_install_reg.log
2007-05-18 22:23:10 2768 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\jusched.log
2007-05-15 01:28:30 35 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\stadistic.log
2007-05-15 01:28:30 995 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\stadistic.zip
2007-05-19 05:22:16 1416 --a------ D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\wmplog00.sqm
2007-05-22 19:49:44 0 d-------- D:\DOCUME~1\CASTIN~1.COM\LOCALS~1\Temp\WPDNSE
2002-07-25 18:13:12 196608 --a------ D:\WINDOWS\Downloaded Program Files\dwusplay.exe <Not Verified; InstallShield Software Corporation; InstallShield Update Service>
2006-02-22 14:14:26 198304 --a------ D:\WINDOWS\Downloaded Program Files\avsniffdlgs.dll <Verified; TODO: <Company name>; TODO: <Product name>>
2006-02-22 14:07:06 537704 --a----c- D:\WINDOWS\Downloaded Program Files\AXXPEE.dll <Verified; WholeSecurity,Inc.; WholeSecurity Confidence Online(tm) for Web Applications>
2004-12-07 16:07:08 32 --a------ D:\WINDOWS\Downloaded Program Files\bdcore.dll
2005-03-01 14:08:48 118784 --a------ D:\WINDOWS\Downloaded Program Files\bdupd.dll
2002-07-25 18:13:18 24576 --a------ D:\WINDOWS\Downloaded Program Files\dwusplay.dll <Not Verified; InstallShield Software Corporation; InstallShield Update Service>
2006-05-17 14:26:12 42112 --a------ D:\WINDOWS\Downloaded Program Files\ecmldr32.dll <Verified; Symantec Corp.; ECOM Loader>
2006-09-27 01:00:00 272040 --a------ D:\WINDOWS\Downloaded Program Files\ecmsvr32.dll <Verified; Symantec Corporation; ECOM Server>
2005-03-01 14:08:52 53248 --a------ D:\WINDOWS\Downloaded Program Files\ipsupd.dll
2004-06-16 06:02:10 323584 --a------ D:\WINDOWS\Downloaded Program Files\isusweb.dll <Not Verified; InstallShield Software Corporation; InstallShield Update Service>
2004-12-07 16:07:08 32 --a------ D:\WINDOWS\Downloaded Program Files\libfn.dll
2006-02-22 14:09:04 201896 --a------ D:\WINDOWS\Downloaded Program Files\navapi32.dll <Verified; Symantec Corp.; NAVAPI>
2006-09-27 01:00:00 124584 --a------ D:\WINDOWS\Downloaded Program Files\naveng32.dll <Verified; Symantec Corporation; Symantec Antivirus Engine>
2006-09-27 01:00:00 882344 --a------ D:\WINDOWS\Downloaded Program Files\navex32a.dll <Verified; Symantec Corporation; Symantec Antivirus Engine>
2006-05-31 04:15:16 10 --a------ D:\WINDOWS\Downloaded Program Files\oscan81.ocx_x
-*- End of Logfile -*-
Ok Répondre à alexdarcy | Bien
Clic sur démarrer, poste de travail, D:, et supprime les dossiers suivants :
- Deckard
- VundoFix Backups
¤ Clic sur démarrer, poste de travail, D:, Windows, system32 et supprime :
- Panda Software
- ActiveScan
Ton PC semble propre de plus des différents scans que tu as fais, pas grand chose à du ressortir des rapports ?
A mes yeux c'est propre ;-)
c'est en forgeant que l'on devient forgeron !
** site perso pour forger, dans mon profil ** Répondre à boulepate62 |
| C'est fait.
Je vais essayer d'éteindre et de ralumer Windows pour voir si cette fenetre arrive toujours.
Je te le dirai
merci de m'aider boulepate
alex Répondre à alexdarcy |
| Eh non! elle arrive toujours cette fenetre furtive "gialog". C'est une minie fenetre grise qui s'ouvre au centre du bureau de 1 et 2 secondes. A ton avis c'est koi ? Qu'est-ce qui l'a fait obstinément s'ouvrir ?
En plus je vais m'absenter kelk jours. On reprend contact à mon retour. Ok ? je compte bien sur toi mon boulepate.
Alex Répondre à alexdarcy | Rends toi sur se site
http://www.virustotal.com/en/virustotalx.html
En haut à droite clic sur "choisir"
Tu vas dans C:, windows, system32 tu cherches le processus ci-dessous et tu clic sur "ouvrir"
D:\WINDOWS\system32\drivers\klick.dat
dès que c'est fait, clic sur "send"
Tu attends un peu qu'il analyse ton fichier ça peut duré plusieurs minutes et colle le rapport ici une fois qu'il a terminé stp
Fais la même chose avec celui-ci
D:\WINDOWS\system32\drivers\fidbox.dat
ET
Fais un clic droit sur cette url et choisis enregistrer sous Ton Bureau
http://www.silentrunners.org/Silent%20Runners.vbs
Double-clic dessus sur Silent Runners.vbs. Clic sur Oui au message qui apparaîtra puis ok
Attends quelques minutes. Un message va apparaître clic sur OK.
Puis copie et colle ici le contenu du rapport Startup Program.... qu'il a créé sur ton bureau
c'est en forgeant que l'on devient forgeron !
** site perso pour forger, dans mon profil ** Répondre à boulepate62 | Bonjour Boulepate
voici le rapport pour D:\WINDOWS\system32\drivers\klick.dat :
STATUS: QUEUEDYour file "klick.dat" is queued in position: 85. Estimated start time is between 12 and 17 minutes.
Antivirus Version Update Result
Aditional Information
voici le rapport pour D:\WINDOWS\system32\drivers\fidbox.dat :
0 bytes size received / Se ha recibido un archivo vacio
JE NE SAIS PAS SI C EST BIEN LE RAPPORT ATTENDU MAIS C EST CE QUI ETAIT AFFICHE ...
Enfin voici le rapport de Startup Programs :
"Silent Runners.vbs", revision R50, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""D:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"" ["Nero AG"]
"msnmsgr" = ""D:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"MaxtorOneTouch" = "D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" ["Maxtor"]
"NeroFilterCheck" = "D:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" ["Nero AG"]
"PinnacleDriverCheck" = "D:\WINDOWS\system32\\PSDrvCheck.exe" [empty string]
"NvCplDaemon" = "RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
"NvMediaCenter" = "RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]
"AVP" = ""D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"" ["Kaspersky Lab"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll" ["Sun Microsystems, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
-> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "D:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
Ok Répondre à alexdarcy |
| Lol
non voici le rapport attendu de D:\WINDOWS\system32\drivers\klick.dat :
STATUS: SCANNINGFile "klick.dat" received on 05.29.2007 at 17:25:08 (CET) is being scanned by VirusTotal in this moment. Results will be shown as they're generated.
Antivirus Version Update Result
AhnLab-V3 2007.5.30.0 05.29.2007 no virus found
AntiVir 7.4.0.27 05.29.2007 no virus found
Authentium 4.93.8 05.23.2007 no virus found
Avast 4.7.997.0 05.29.2007 no virus found
AVG 7.5.0.467 05.29.2007 no virus found
BitDefender 7.2 05.29.2007 no virus found
CAT-QuickHeal 9.00 05.29.2007 no virus found
ClamAV devel-20070416 05.29.2007 no virus found
DrWeb 4.33 05.29.2007 no virus found
eSafe 7.0.15.0 05.28.2007 no virus found
Aditional Information
File size: 82258 bytes
MD5: dd09de94b804012144a637020aae2e64
Ok Répondre à alexdarcy |
|
|
|
|
|