Bonsoir a tous
Ceci s.t.p pour déjà mettre le pc propre.
* Copie le tout le texte présent dans l'encadré ci-dessous (tu le sélectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C)
- Code: Tout sélectionner
M3 - MFPP: Plugins - [monocoque] -- C:\Program Files\Mozilla FireFox\searchplugins\babylon.xml => Infection PUP (Toolbar.Babylon)*
P2 - FPN: [HKLM] [@www.dlmanager.net/omaha/tools//Software Update;version=8] - (.Boxore OU. - Software Update.) -- C:\Program Files\Software\Update\1.2.199.0\npSoftwareOneClick8.dll => Infection PUP (Adware.Boxore)*
O23 - Service: Software Update Service (supdate) (supdate) . (...) - C:\Program Files\Software\Update\SoftwareUpdate.exe (.not file.) => Infection Diverse (Adware.Boxore)
[MD5.00000000000000000000000000000000] [APT] [SoftwareUpdateTaskMachineCore] (...) -- C:\Program Files\Software\Update\SoftwareUpdate.exe (.not file.) [0] => Infection Diverse (Adware.Boxore)
[MD5.00000000000000000000000000000000] [APT] [SoftwareUpdateTaskMachineUA] (...) -- C:\Program Files\Software\Update\SoftwareUpdate.exe (.not file.) [0] => Infection Diverse (Adware.Boxore)
[HKCU\Software\AppDataLow\Software\Smartbar] => Infection PUP (Hijacker.SmartBar)*
[HKCU\Software\InstallCore] => Infection PUP (Adware.InstallCore)
[HKLM\Software\Babylon] => Infection PUP (Toolbar.Babylon)*
O43 - CFD: 21/08/2012 - 23:37:32 - [1,080] ----D C:\Program Files\Software => Infection PUP (Adware.Boxore)
O43 - CFD: 21/08/2012 - 23:37:28 - [0,007] ----D C:\Documents and Settings\monocoque\Application Data\Babylon => Infection PUP (Toolbar.Babylon)*
O43 - CFD: 21/08/2012 - 23:42:00 - [0] ----D C:\Documents and Settings\monocoque\Local Settings\Application Data\Software => Infection PUP (Adware.Boxore)
O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (supdate) .(...) - LEGACY_SUPDATE => Infection PUP (Adware.Boxore)
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("browser.newtab.url", "http://search.babylon.com/?affID=110808&tt=3412_7&babsrc=NT_ss&mntrId=14607ff800000000000090e6bab[...] => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("browser.search.order.1", "Search the web (Babylon)"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.admin", false); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.aflt", "babsst"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.dfltLng", "en"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.excTlbr", false); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.id", "14607ff800000000000090e6bab95488"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.instlDay", "15573"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.instlRef", "sst"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://www.google.com/search?babsrc=TB_ggl&q="); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.vrsn", "1.6.4.6"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar.vrsni", "1.6.4.6"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.babExt", ""); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110808&tt=3412_7"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.newTab", true); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.newTabUrl", "http://search.babylon.com/?affID=110808&tt=3412_7&babsrc=NT_ss&mntrId=14607ff8[...] => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); => Infection PUP (Toolbar.Babylon)*
O69 - SBI: prefs.js [monocoque - 646kdpn5.default] user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.4.623:37:52"); => Infection PUP (Toolbar.Babylon)*
[HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] => Infection PUP (Toolbar.Babylon)
[HKLM\Software\Classes\Interface\{22B0769F-794B-4422-AC84-47B123C8986D}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{255E0B2A-D747-4EEF-B7CE-159D73A3656D}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{28ED590D-F5ED-4E05-A87F-1D759F1C6169}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\AppID\{32451DFC-C23B-4E12-866C-FC7982238504}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\CLSID\{32451DFC-C23B-4E12-866C-FC7982238504}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\Interface\{45D5B93F-E2ED-4AF2-915E-DCDDBDA8C33C}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\TypeLib\{48C9C8B0-A546-46C1-A81F-47A31E623E9D}] => Infection PUP (Adware.Incredibar)
[HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Adware.IncrediBar)
[HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Adware.IncrediBar)
[HKLM\Software\Classes\CLSID\{63435521-BE15-44D9-A4BE-A5A0000D9662}] => Infection PUP (Adware.Boxore)
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{63435521-BE15-44D9-A4BE-A5A0000D9662}] => Infection PUP (Adware.Boxore)
[HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63435521-BE15-44D9-A4BE-A5A0000D9662}] => Infection PUP (Adware.Boxore)
[HKLM\Software\Classes\Interface\{771B99AB-636F-4A11-9039-8DFEB927B061}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{A8321AA2-2227-40C7-8525-6C2F4E1B0EBE}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{AA41A731-6814-4A70-A6F1-C0A20FBBFBD5}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{ABBB8A9E-D8AF-40D1-94BE-5175077465FC}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] => Infection PUP (Adware.Funmoods)
[HKLM\Software\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\Interface\{BF737694-56F6-46FA-9FDC-FA99A5B25FAD}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{CFCD164E-8AC9-478E-9ECC-B616A932016C}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\Interface\{D5961CC0-B442-4567-8030-67E241EF4CC2}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection PUP (Adware.Funmoods)
[HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection PUP (Adware.Funmoods)
[HKLM\Software\Classes\Interface\{E450067F-1C93-41A7-928E-07E5C2EEC680}] => Infection PUP (Adware.IncrediBar)
[HKLM\Software\Classes\AppID\escort.dll] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\escortapp.dll] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\escorteng.dll] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\esrv.EXE] => Infection PUP (PUP.Funmoods)
[HKLM\Software\Classes\escort.escortIEPane] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\escort.escortIEPane.1] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BA086F2D38A8E1A47912955A68B3AD24] => Infection PUP (Adware.PredictAd)
[HKLM\Software\Classes\Prod.cap] => Infection PUP (Toolbar.Babylon)
[HKLM\Software\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] => Infection PUP (Adware.Boxore)
[HKLM\Software\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] => Infection PUP (Adware.Boxore)
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] => Infection PUP (Adware.Boxore)
[HKCU\Software\InstallCore] => Infection PUP (Adware.InstallCore)
[HKLM\SYSTEM\CurrentControlSet\Services\supdate] => Infection PUP (Adware.Boxore)
[HKLM\Software\Classes\AppID\ESRV.EXE] => Infection PUP (PUP.Funmoods)
[HKLM\Software\Classes\AppID\escort.DLL] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\escortApp.DLL] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\escortEng.DLL] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Classes\AppID\escorTlbr.DLL] => Infection PUP (PUP.Funmoods)*
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] => Infection PUP (Adware.Boxore)
C:\Program Files\Software => Infection PUP (Adware.Boxore)
C:\Documents and Settings\monocoque\Application Data\Babylon => Infection PUP (Toolbar.Babylon)*
C:\Documents and Settings\monocoque\Local Settings\Application Data\Software => Infection PUP (Adware.Boxore)
SS - | Auto 0 | (supdate) . (...) - C:\Program Files\Software\Update\SoftwareUpdate.exe => Infection Diverse (Adware.Boxore)
[HKCU\Software\Conduit] => Toolbar.Conduit
[HKCU\Software\Softonic] => Toolbar.Conduit*
[HKLM\Software\Classes\CLSID\{092A2C6B-43EE-4F9F-8F8E-14ED5E11C14B}] => Toolbar.Agent
[HKLM\Software\Classes\CLSID\{257A6158-1416-4B31-9BF8-29FF49F3814F}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{736EF78E-5A04-46F9-893E-EDEC6EA5DF45}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{7A1BCE27-099C-4628-B63A-AEC00C6376B3}] => Toolbar.Agent
[HKLM\Software\Classes\CLSID\{AC5C4189-A8A0-4C9D-8910-C9CEF8360077}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{AF3AFF7C-B9E9-48DD-9002-212B6DEAAC02}] => Toolbar.Agent
[HKLM\Software\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] => Toolbar.Wajam
[HKLM\Software\Classes\Interface\{DBE82879-914A-422F-BAE9-2ECC80BE536F}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{E12D7149-73EF-45E4-A1E9-99FD7DAE62D3}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{F2B184F1-547C-4EE9-BFC4-AC489C7077D9}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{F977D9F2-4BDC-44A6-B508-7C0284C61EED}] => Toolbar.Agent
[HKLM\Software\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] => Toolbar.ZoneAlarm
[HKLM\Software\Classes\CLSID\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}] => Toolbar.ZoneAlarm
[HKLM\Software\Classes\Software.OneClickCtrl.8] => Toolbar.Agent
[HKCU\Software\Softonic] => Toolbar.Conduit*
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Protection_ZoneAlarm Toolbar] => Toolbar.ZoneAlarm
O2 - BHO: Blog This in Windows Live - {2adefb8e-b923-35e6-86e2-2b7841f5d6a4} . (...) -- mscoree.dll (.not file.)
O4 - HKCU\..\Run: [MTool] C:\Documents and Settings\monocoque\Application Data\MCommon\MTool_new.exe (.not file.)
O4 - HKUS\S-1-5-21-507921405-261903793-682003330-1003\..\Run: [MTool] C:\Documents and Settings\monocoque\Application Data\MCommon\MTool_new.exe (.not file.)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\At1.job [296]
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job [400]
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\SoftwareUpdateTaskMachineCore.job [1076]
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\SoftwareUpdateTaskMachineUA.job [1080]
FirewallRaz
EmptyFlash
Emptytemp
SysRestore
Puis Lance ZHPFix depuis le raccourci du bureau.
-> laisse travailler l'outil et ne touche à rien ...
Une fois terminée, un nouveau rapport s'affiche : copie/colle le contenu de ce dernier dans ta prochaine réponse ...
(ce rapport est en outre sauvegardé dans ce dossier > C:\Program files\ZHPDiag\ZHPFixReport.txt)
Important : s'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le de suite !
Ensuite:Télécharge
AdwCleaner ( d'Xplode ) sur ton bureau.
http://general-changelog-team.fr/telech ... adwcleaner - Lances le en
mode normal , puis cliques sur
[Suppression] - Lorsque le message indiquant qu'AdwCleaner a détecté une variante spécifique d'adware s'affiche , cliquez sur
[OK] - L'ordinateur va redémarrer tout seul. Redémarre-le en mode normal.
- AdwCleaner s'ouvrira normalement, avec comme seul choix possible
[Suppression] - Cliquez dessus, puis patientes pendant la suppression.
- Une fois la suppression effectuée, AdwCleaner vous invitera à redémarrer l'ordinateur
- Au redémarrage, un rapport s'ouvrira. Postes le sur le forum.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Ensuite pour une bonne sécurité, bien mettre son pc a jour.
Windows XP Professional Service Pack 2 on est au SP3
Ensuite:
C'est à dire: Comment savoir si un ordinateur a été visité à distance (même si il y a 6 mois).
Impossible si tel ou tel intrus a réussi a enlever ses traces.
Pour les traces possible suivant un texte pas de trace de
keylogger sur le pc.
après comme désigné par mes amis
on ne peux tout voir et quelques fois juste un pro et un prix
pôur vérifier cela et encore.
Je ne vias pas plus entrer dans les possibilté que quelques d'autres est pu donner des infos perso a une autre personne.
Fait mes demandes s.t.p.
PS dans un cas de suspicion surtout en premier changer ses mots de passe.
Important