Virus

Anonyme
2014-01-23T09:21:20+00:00

bonjour,

1-  Lors de chaque ouverture de l"ordi,il apparait une fenetre d'erreur " universal updater "et j'envoie regulierement les messages d'erreur.

2- la mise en route de l'ordi est lente.

3-Lorsque j'arrive à ma page d'accueil google avec I.E. il vbeut déjà me bloquer le contenu de cette page avant que je tape quoique ce soit .

4- J'ai parfois des fenetres intempestives de pub.

       Comme action j'ai fait un scan avec Microsoft safety scanner .Il m'a trouvé 4 fichiers infectes et a supprimé 2 logiciels " malveillants " qui sont

" Trojan:win32/Bumat!rts et Trojan.dropper:win32/Rotbrow:l

Malgrè ça les problemes persistent tout de meme.

Je vous remercie par avance de votre aide

Gilbert

Windows pour les particuliers | Versions antérieures de Windows | Sécurité et confidentialité

Question verrouillée. Cette question a été migrée à partir de la Communauté Support Microsoft. Vous pouvez voter pour indiquer si elle est utile, mais vous ne pouvez pas ajouter de commentaires ou de réponses ni suivre la question.

0 commentaires Aucun commentaire

61 réponses

Trier par : Les plus anciens
  1. Anonyme
    2014-01-23T14:14:07+00:00

    Hello gilbertchayne !

    Bonjour papynet,

     

    Si je dit que j'aui un virus c'est que j'en suis certain
    regarde  bien tout le sujet bdepuis le début

    Je l'avais lu  et c'est pour cela que j'avais donné le lien vers ma procédure de décontamination

    donc Excusez moi !


    Bien cordialement,
    Georges
    Forum :  http://saamu.net/
     Contactez moi  :  http://papynet.mvps.org/MailToMP.htm

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire
  2. Anonyme
    2014-01-23T18:55:21+00:00

    Bonsoir Papynet

    voici le rapport~ Rapport de ZHPDiag v2014.1.17.19 - Nicolas Coolman  (17/01/2014)

    ~ Lancé par user (23/01/2014 18:57:11)

    ~ Adresse du Site Web  http://nicolascoolman.webs.com

    ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/

    ~ Traduit par Nicolas Coolman

    ~ Etat de la version :

    ~ Liste blanche : Activée par le programme

    ~ Elévation des Privilèges : OK

    ~ User Account Control (UAC): Not Found

    ---\ Navigateurs Internet

    MSIE: Internet Explorer v8.0.6001.18702 (Defaut)

    GCIE: Google Chrome v32.0.1700.76

    ---\ Informations sur les produits Windows

    ~ Langage: Français

    Microsoft Windows XP, 32-bit Service Pack 3 (Build 2600)

    Windows Automatic Updates : OK

    Windows Genuine Advantage : OK

    ---\ Logiciels de protection du système

    avast! Free Antivirus v9.0.2011

    ---\ Logiciels d'optimisation du système

    CCleaner v3.28 =>Piriform Ltd

    ---\ Logiciels de partage PeerToPeer

    ---\ Surveillance de Logiciels

    Adobe Flash Player 11 Plugin

    ---\ Informations sur le système

    ~ Processor: x86 Family 15 Model 28 Stepping 0, AuthenticAMD

    ~ Operating System: 32 Bits

    Boot mode: Normal (Normal boot)

    Total RAM: 1023 MB (54% free)

    System Restore: Activé (Enable)

    System drive C: has 124 GB (82%) free of 149 GB

    ---\ Mode de connexion au système

    ~ Computer Name: MMMMMM

    ~ User Name: user

    ~ All Users Names: user, SUPPORT_388945a0, Michelle, HelpAssistant, Administrateur,

    ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89

    Logged in as Administrator

    ---\ Variables d'environnement

    ~ System Unit : C:\

    ~ %AppZHP% : C:\Documents and Settings\user\Application Data\ZHP\

    ~ %AppData% : C:\Documents and Settings\user\Application Data\

    ~ %Desktop% : C:\Documents and Settings\user\Bureau\

    ~ %Favorites% : C:\Documents and Settings\user\Favoris\

    ~ %LocalAppData% : C:\Documents and Settings\user\Local Settings\Application Data\

    ~ %StartMenu% : C:\Documents and Settings\user\Menu Démarrer\

    ~ %Windir% : C:\WINDOWS\

    ~ %System% : C:\WINDOWS\system32\

    ---\ Enumération des unités disques

    A: Floppy drive, Flash card reader, USB Key (Not Inserted)

    C: Hard drive, Flash drive, Thumb drive (Free 124 Go of 149 Go)

    D: CD-ROM drive (Not Inserted)

    G: Hard drive, Flash drive, Thumb drive (Free 253 Go of 298 Go)

    ---\ Etat du Centre de Sécurité Windows

    ~ Security Center: 42 Legitimates Filtered in 00mn 00s

    ---\ Recherche particulière de fichiers génériques

    [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\Explorer.exe [1037824]

    [MD5.897CA9DA6F568E24549719D5676385A1] - (.Microsoft Corporation - Internet Extensions for Win32.) (.29/10/2013 - 08:57:02.) -- C:\WINDOWS\system32\wininet.dll [920064]

    [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]

    [MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/08/2011 - 14:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496]

    [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 - 12:40:32.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]

    [MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744]

    [MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976]

    [MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672]

    [MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384]

    [MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) (.13/04/2008 - 19:00:54.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144]

    [MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112]

    [MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832]

    [MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264]

    [MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 14:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320]

    [MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816]

    [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]

    [MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384]

    [MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328]

    [MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 11:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]

    [MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.13/04/2008 - 19:57:36.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752]

    [MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/04/2008 - 12:00:00.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376]

    ~ Generic Processes:  Scanned in 00mn 00s

    ---\ Etat des fichiers cachés (Caché/Total)

    ~ Mes images (My Pictures) : 0/8

    ~ Mes musiques (My Musics) : 0/0

    ~ Mes Videos (My Videos) : 0/0

    ~ Mes Favoris (My Favorites) : 1/29

    ~ Mes Documents (My Documents) : 0/170

    ~ Mon Bureau (My Desktop) : 0/5343

    ~ Menu demarrer (Programs) : 1/33

    ~ Hidden Files:  Scanned in 00mn 00s

    ---\ Processus lancés

    [MD5.D01BD16ACAB7D7744F8C397EAEBB8798] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINDOWS\system32\Ati2evxx.exe   [405504] [PID.808]

    [MD5.D74884939D53612FD84AC82C59CCFE27] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe   [50344] [PID.1352]

    [MD5.ABDD5AD016AFFD34AD40E944CE94BF59] - (.SEIKO EPSON CORPORATION - eEBAPI Core Process module.) -- C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe   [94208] [PID.2016]

    [MD5.B33CF4DE909A5B30F526D82053A63C8E] - (.ABBYY - ABBYY network license server.) -- C:\Program Files\Fichiers communs\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe   [759048] [PID.288]

    [MD5.5E9A6658A2A69AE7EB195113B7A2E7A9] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe   [44544] [PID.2832]

    [MD5.37FFF683AEE7F09F5F7087138192BF02] - (.NVIDIA Corporation - NVIDIA nForce Mixer Tray Application.) -- C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe   [131072] [PID.1224]

    [MD5.0E34B7BB1FCF22BCC1E394D16F9E992B] - (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe   [30040] [PID.1696]

    [MD5.D3AC38E80E928CC61A22650E04423BB8] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe   [979328] [PID.2596]

    [MD5.AFEBF9E0B223FF04709F747C172D3540] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe   [3764024] [PID.3136]

    [MD5.E13EA4860E8F2AA845B53BFD2B6FEC5B] - (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe   [1695232] [PID.3516]

    [MD5.B4B60197F696B9B239478A97CCC6CD48] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHBE.exe   [212480] [PID.980]

    [MD5.C7D472D1F14E0C51F048C49FAFB42F90] - (.Orbiscom Ltd. All rights reserved. - ECBL Client.) -- C:\Program Files\e-Carte Bleue Société Générale\ecbl-sg.exe   [278528] [PID.2668]

    [MD5.32C26797AB646074A2BB562F9D10ADB5] - (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.exe   [97680] [PID.3092]

    [MD5.B60DDDD2D63CE41CB8C487FCFBB6419E] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe   [638816] [PID.3244]

    [MD5.8E5651B04BE775696B32F7F1F5DA8871] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe   [8336896] [PID.3256]

    ~ Processes Running:  Scanned in 00mn 01s

    ---\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)

    C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

    G1 - GCS: Preference [User Data\Default] http://www.nationzoom.com =>Hijacker.NationZoom

    G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)

    G2 - GCE: Preference [User Data\Default] [oleglodmkonbpfmlffapjfednjopbeeh] HD Streamer v.1.1.1.0 (Activé)

    ~ Google Browser: 12 Legitimates Filtered in 00mn 01s

    ---\ Internet Explorer, Proxy Management (R5)

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1

    ~ Proxy management:  Scanned in 00mn 00s

    ---\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs

    F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe,

    F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe

    F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

    ~ Keys:  Scanned in 00mn 00s

    ---\ Hosts file redirection (O1)

    ~ Le fichier hosts est sain (The hosts file is clean).

    ~ Hosts File:  Scanned in 00mn 00s

    ~ Nombre de lignes (Lines number): 20

    ---\ Browser Helper Objects de navigateur (O2)

    O2 - BHO: HD Streamer - {E6062A33-016E-4BDA-A6F1-890D989F8656} . (.HD Streamer - ScriptHost.) -- C:\Program Files\HD Streamer\ScriptHost.dll

    ~ BHO: 12 Legitimates Filtered in 00mn 00s

    ---\ Internet Explorer Toolbars (O3)

    O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION - Epson Easy Photo Print (TBL).) -- C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll

    O3 - Toolbar: avast! Online Security - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

    O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google

    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{01E04581-4EEE-11D0-BFE9-00AA005B4383} Clé orpheline

    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{0E5CBF21-D15F-11D0-8301-00AA005B4383} Clé orpheline

    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline

    ~ Toolbar:  Scanned in 00mn 00s

    ---\ Autres liens utilisateurs (O4)

    O4 - GS\Program [AllUsers]: MSN.lnk . (.Microsoft Corporation - Win32 Cabinet Self-Extractor.)  -- C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe  =>.Microsoft Corporation

    O4 - GS\Program [AllUsers]: Windows Desktop Search.lnk . (.Microsoft Corporation - Windows Desktop Search System Tray.)  -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    O4 - GS\Program [AllUsers]: Windows Messenger.lnk . (.Microsoft Corporation - Windows Messenger.)  -- C:\Program Files\Messenger\msmsgs.exe

    O4 - GS\Program [user]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.)  -- C:\Program Files\Internet Explorer\iexplore.exe

    O4 - GS\Program [user]: Lecteur Windows Media.lnk . (.Microsoft Corporation - Lecteur Windows Media.)  -- C:\Program Files\Windows Media Player\wmplayer.exe  =>.Microsoft Corporation

    O4 - GS\Program [Michelle]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.)  -- C:\Program Files\Internet Explorer\iexplore.exe

    O4 - GS\Program [Michelle]: Lecteur Windows Media.lnk . (.Microsoft Corporation - Lecteur Windows Media.)  -- C:\Program Files\Windows Media Player\wmplayer.exe  =>.Microsoft Corporation

    O4 - GS\Program [Administrateur]: Lecteur Windows Media.lnk . (.Microsoft Corporation - Lecteur Windows Media.)  -- C:\Program Files\Windows Media Player\wmplayer.exe  =>.Microsoft Corporation

    ~ Global Startup: 18 Legitimates Filtered in 00mn 00s

    ---\ Applications lancées au démarrage du sytème (O4)

    O4 - GS\Program [AllUsers]: e-Carte Bleue Société Générale.lnk . (.Orbiscom Ltd. All rights reserved. - ECBL Client.)  -- C:\Program Files\e-Carte Bleue Société Générale\ecbl-sg.exe

    O4 - GS\Program [AllUsers]: Windows Desktop Search.lnk . (.Microsoft Corporation - Windows Desktop Search System Tray.)  -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    O4 - GS\Program [user]: OneNote 2007 - Capture d'écran et lancement.lnk . (.Microsoft Corporation - Microsoft Office OneNote Quick Launcher.)  -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.exe

    O4 - HKLM..\Run: [NVMixerTray] . (.NVIDIA Corporation - NVIDIA nForce Mixer Tray Application.) -- C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe

    O4 - HKLM..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    O4 - HKLM..\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe

    O4 - HKLM..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe

    O4 - HKCU..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe

    O4 - HKCU..\Run: [EPSON SX440 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHBE.exe  =>.Epson Seiko Corporation

    O4 - HKCU..\Run: [HD Streamer Sync] . (...) -- C:\Documents and Settings\user\Local Settings\Application Data\HD Streamer\crxmon.exe

    O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-21-583907252-1336601894-1801674531-1003..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-21-583907252-1336601894-1801674531-1003..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe

    O4 - HKUS\S-1-5-21-583907252-1336601894-1801674531-1003..\Run: [EPSON SX440 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHBE.exe  =>.Epson Seiko Corporation

    O4 - HKUS\S-1-5-21-583907252-1336601894-1801674531-1003..\Run: [HD Streamer Sync] . (...) -- C:\Documents and Settings\user\Local Settings\Application Data\HD Streamer\crxmon.exe

    ~ Application:  Scanned in 00mn 00s

    ---\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)

    O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO

    O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Clé orpheline

    O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe

    ~ IE Extra Buttons:  Scanned in 00mn 00s

    ---\ Objets ActiveX (Downloaded Program Files)(O16)

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} ((no name)) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1361769193015

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} ((no name)) - http://download.eset.com/special/eos/OnlineScanner.cab

    ~ Objets ActiveX:  Scanned in 00mn 00s

    ---\ Modification Domaine/Adresses DNS (O17)

    O17 - HKLM\System\CCS\Services\Tcpip..{D97B1155-B58C-4A6A-8E5C-BE267AE37FEF}: DhcpNameServer = 192.168.1.1 192.168.1.1

    O17 - HKLM\System\CS1\Services\Tcpip..{D97B1155-B58C-4A6A-8E5C-BE267AE37FEF}: DhcpNameServer = 192.168.1.1 192.168.1.1

    O17 - HKLM\System\CS2\Services\Tcpip..{D97B1155-B58C-4A6A-8E5C-BE267AE37FEF}: DhcpNameServer = 192.168.1.1 192.168.1.1

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1

    ~ Domain:  Scanned in 00mn 00s

    ---\ Protocole additionnel (O18)

    O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll  =>.Microsoft Corporation

    O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.dll  =>.Microsoft Corporation

    ~ Protocole Additionnel:  Scanned in 00mn 00s

    ---\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

    O20 - Winlogon Notify: AtiExtEvent . (.ATI Technologies Inc. - ATI External Event Utility DLL Module.) -- C:\WINDOWS\system32\Ati2evxx.dll

    O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll

    O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll

    O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll

    O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll

    O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll

    O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll

    O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll

    O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll

    O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll

    O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\WINDOWS\system32\WgaLogon.dll

    O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll

    ~ Winlogon:  Scanned in 00mn 00s

    ---\ Liste des services NT non Microsoft et non désactivés (O23)

    O23 - Service: MgAssist Service (MgAssistService) . (...) - C:\Program Files\Mobogenie\MgAssist.exe (.not file.)

    O23 - Service: Universal Updater Service (UniversalUpdater) . (.Pas de propriétaire - Universal Updater.) - C:\Program Files\Universal Updater\UpdaterService.exe =>Adware.IncrediBar

    ~ Services: 6 Legitimates Filtered in 00mn 04s

    ---\ Enumération Active Desktop & MHTML Editor (O24)

    O24 - Desktop Component 0: (no name) - file:http://webmail1p.orange.fr/webmail/fr_FR/Extension_icons/70_70/picto_word.gif

    O24 - Desktop General: BackupWallPaper - .(...) - C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

    O24 - Desktop General: WallPaper - .(...) - C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

    ~ Desktop Component: 4 Legitimates Filtered in 00mn 00s

    ---\ Pilotes lancés au démarrage du système (O41)

    O41 - Driver:  (iSafeNetFilter) . (. - .) - C:\Program Files\iSafe\iSafeNetFilter.sys (.not file.) =>Trojan.Staser

    ~ Drivers: 75 Legitimates Filtered in 00mn 00s

    ---\ Logiciels installés (O42)

    O42 - Logiciel: HD Streamer - (.HD Streamer.) [HKLM] -- HD Streamer

    O42 - Logiciel: Mots fléchés - (...) [HKLM] -- Mots Fléchés

    ~ Logic: 21 Legitimates Filtered in 00mn 00s

    ---\ HKCU & HKLM Software Keys

    [HKCU\Software\ForumerIT] =>Toolbar.Forumer

    [HKCU\Software\HD Streamer]

    [HKCU\Software\IncrediMail]

    [HKLM\Software\Universal]

    [HKLM\Software\iSafe] =>Trojan.Staser

    ~ Key Software: 161 Legitimates Filtered in 00mn 00s

    ---\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

    O43 - CFD: 14/10/2013 - 14:29:34 - [31,928] ----D C:\Program Files\FMots

    O43 - CFD: 23/01/2014 - 13:33:35 - [2,326] ----D C:\Program Files\HD Streamer

    O43 - CFD: 20/01/2014 - 14:43:43 - [0] ----D C:\Program Files\maucampo

    O43 - CFD: 20/01/2014 - 14:42:26 - [0,383] ----D C:\Program Files\Universal Updater

    O43 - CFD: 27/04/2013 - 12:16:28 - [0] ----D C:\Documents and Settings\All Users\Application Data\IM

    O43 - CFD: 20/01/2014 - 14:42:36 - [0,123] ----D C:\Documents and Settings\user\Local Settings\Application Data\HD Streamer

    O43 - CFD: 27/04/2013 - 14:26:52 - [24,597] ----D C:\Documents and Settings\user\Local Settings\Application Data\IM

    ~ Program Folder: 121 Legitimates Filtered in 00mn 18s

    ---\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

    O44 - LFC:[MD5.C9DD76D0EF94637C77FF8CA5E0FB0684] - 19/01/2014 - 15:02:35 ---A- . (...) -- C:\WINDOWS\system.ini   [227]

    O44 - LFC:[MD5.EE9D8B7FAD6E066F255E7598D3CB25F4] - 19/01/2014 - 15:02:35 ---A- . (...) -- C:\WINDOWS\win.ini   [552]

    O44 - LFC:[MD5.EAE2066DB230C5CBAAA52D262A0B6AFE] - 19/01/2014 - 15:45:44 ---A- . (...) -- C:\PhysicalMBR.bin   [512]

    O44 - LFC:[MD5.3FF8F2CED96FDDB346C3C9ED8CF010AA] - 20/01/2014 - 14:32:16 ---A- . (...) -- C:\WINDOWS\ExplorerXP.INI   [26]

    O44 - LFC:[MD5.55CC217122859A8CEE409FAC860E132B] - 21/01/2014 - 07:01:48 ---A- . (...) -- C:\DelFix.txt   [5136]

    O44 - LFC:[MD5.BCD90DE67A367CE8962EF8565B13C56D] - 23/01/2014 - 18:46:41 ---A- . (...) -- C:\WINDOWS\wiaservc.log   [50]

    O44 - LFC:[MD5.3105A18B3D8610CE24CF5FC126F9F9CF] - 23/01/2014 - 18:46:42 ---A- . (...) -- C:\WINDOWS\wiadebug.log   [159]

    ~ Files: 21 Legitimates Filtered in 00mn 04s

    ---\ Opérations et fonctions au démarrage de Windows Explorer (O46)

    O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll

    O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O46 - SEH:ShellExecuteHooks - Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll

    ~ ShellExecuteHooks:  Scanned in 00mn 00s

    ---\ Export de clé d'application autorisée (O47)

    O47 - AAKE:Key Export SP - "D:\Network\EpsonNetSetup\ENEasyApp.exe" [Enabled] .(...) -- D:\Network\EpsonNetSetup\ENEasyApp.exe (.not file.)

    O47 - AAKE:Key Export SP - "C:\Program Files\IncrediMail\Bin\IncMail.exe" [Enabled] .(...) -- C:\Program Files\IncrediMail\Bin\IncMail.exe (.not file.)

    O47 - AAKE:Key Export SP - "C:\Program Files\IncrediMail\Bin\ImApp.exe" [Enabled] .(...) -- C:\Program Files\IncrediMail\Bin\ImApp.exe (.not file.)

    O47 - AAKE:Key Export SP - "C:\Program Files\IncrediMail\Bin\ImpCnt.exe" [Enabled] .(...) -- C:\Program Files\IncrediMail\Bin\ImpCnt.exe (.not file.)

    ~ Keys Export: 13 Legitimates Filtered in 00mn 00s

    ---\ Contrôle du Safe Boot (CSB) (O49)

    O49 - CSB:Control Safe Boot HKLM...\CCS\Minimal\48799011.sys . (...) -- C:\WINDOWS\system32\Drivers\48799011.sys (.not file.)

    O49 - CSB:Control Safe Boot HKLM...\CCS\Network\48799011.sys . (...) -- C:\WINDOWS\system32\Drivers\48799011.sys (.not file.)

    ~ CSB: 23 Legitimates Filtered in 00mn 00s

    ---\ Image File Execution Options (IFEO) (O50)

    O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d

    ~ IFEO:  Scanned in 00mn 00s

    ---\ Clé de registre Shell MountPoints2 (MPKS) (O51)

    O51 - MPSK:{6045e66f-817d-11e2-ace4-0010b501df33}\AutoRun\command. (...) -- E:\LaunchU3.exe (.not file.)

    ~ Keys:  Scanned in 00mn 00s

    ---\ Liste des pilotes du système (SDL) (O58)

    O58 - SDL:[MD5.F385467DF95D0A73775CB3B076B8B969] - 03/01/2014 - 17:24:07 ---A- . (...) -- C:\WINDOWS\system32\Drivers\aswRvrt.sys   [49944]

    O58 - SDL:[MD5.1B0662514A68C3A42E60D240C5ABEF28] - 03/01/2014 - 17:24:07 ---A- . (...) -- C:\WINDOWS\system32\Drivers\aswVmm.sys   [180248]

    O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 14/04/2008 - 12:00:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\Drivers\cinemst2.sys   [262528]

    O58 - SDL:[MD5.573C7D0A32852B48F3058CFD8026F511] - 14/04/2008 - 12:00:00 ---A- . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\system32\Drivers\hdaudbus.sys   [144384]

    O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 14/04/2008 - 12:00:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\Drivers\ptilink.sys   [17792]

    O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 14/04/2008 - 12:00:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\Drivers\vdmindvd.sys   [58112]

    O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys   [9037]

    O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\country.sys   [27097]

    O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\himem.sys   [4912]

    O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\key01.sys   [42809]

    O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\keyboard.sys   [42537]

    O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos.sys   [27916]

    O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos404.sys   [29146]

    O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos411.sys   [29370]

    O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos412.sys   [29274]

    O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos804.sys   [29146]

    O58 - SDL:[MD5.CAAA108FD7BF71989946B39704323455] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio.sys   [34000]

    O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio404.sys   [34560]

    O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio411.sys   [35648]

    O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio412.sys   [35424]

    O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 14/04/2008 - 12:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio804.sys   [34560]

    ~ Drivers: 5 Legitimates Filtered in 00mn 02s

    ---\ Liste des outils de désinfection (LATC) (O63)

    O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1  =>.Nicolas Coolman

    ~ ADS:  Scanned in 00mn 00s

    ---\ Associations Shell Spawning (O67)

    O67 - Shell Spawning: <.html> <htmlfile>[HKCU..\open\Command] (.Not Key.)

    ~ FASS Keys: 10 Legitimates Filtered in 00mn 00s

    ---\ Menu de démarrage Internet (SMI) (O68)

    O68 - StartMenuInternet: <chrome.exe> <>[HKLM..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- c:\program files\google\chrome\application\chrome.exe

    O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- c:\program files\google\chrome\application\chrome.exe

    O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe

    ~ Keys:  Scanned in 00mn 00s

    ---\ Recherche d'infection sur les navigateurs internet (SBI) (O69)

    O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com

    O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com

    O69 - SBI: SearchScopes [HKCU] {74BC1EEB-33F1-49A6-BEAE-5F653802EA8E} - (Google) - http://www.google.com

    ~ Keys:  Scanned in 00mn 00s

    ---\ Recherche particulière à la racine du système (SPRF) (O84)

    [MD5.246FE58EFFD357B2078842708155E46C] [SPRF][23/01/2014] (...) -- C:\Documents and Settings\user\Bureau\adwcleaner.exe   [1236282]

    ~ Files: 1 Legitimates Filtered in 00mn 00s

    ---\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

    SS - | Demand 09/10/2013 257416 |  (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    SS - | Demand 14/04/2008 225280 |  (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe

    SS - | Auto 25/02/2013 116648 |  (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe

    SS - | Demand 25/02/2013 116648 |  (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe

    SS - | Demand 02/03/2013 19403

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire
  3. Anonyme
    2014-01-23T19:03:23+00:00

    excuse moi papynet mais je n'arrive pas a faire un copier coller du lien ci-joint ???

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire
  4. Anonyme
    2014-01-24T06:44:07+00:00

    Hello gilbertchayne !

    Appliquez le point 7 de la procédure :
    http://www.saamu.net/topic1545.html#p27406
    Redémarrez le PC

    puis fixez avec zhpfix ceci :

    "-->
       Script ZHPFix
       ShortcutFix
       EmptyFlash
       EmptyTemp
       EmptyCLSID
    G1 - GCS: Preference [User Data\Default] http://www.nationzoom.com =>Hijacker.NationZoom
    O4 - HKCU..\Run: [HD Streamer Sync] . (...) -- C:\Documents and Settings\user\Local Settings\Application Data\HD Streamer\crxmon.exe    => Infection LOP (Possible)
    O4 - HKUS\S-1-5-21-583907252-1336601894-1801674531-1003..\Run: [HD Streamer Sync] . (...) -- C:\Documents and Settings\user\Local Settings\Application Data\HD Streamer\crxmon.exe    => Infection LOP (Possible)
    O23 - Service: Universal Updater Service (UniversalUpdater) . (.Pas de propriétaire - Universal Updater.) - C:\Program Files\Universal Updater\UpdaterService.exe =>Adware.IncrediBar
    O41 - Driver: (iSafeNetFilter) . (. - .) - C:\Program Files\iSafe\iSafeNetFilter.sys (.not file.) =>Trojan.Staser
    [HKLM\Software\iSafe] =>Trojan.Staser
    O43 - CFD: 20/01/2014 - 14:43:43 - [0] ----D C:\Program Files\maucampo   => PUP.Maucampo
    [HKLM\SYSTEM\CurrentControlSet\Services\UniversalUpdater] =>Adware.IncrediBar^
    C:\Documents and Settings\user\Local Settings\Application Data\Temp\Iminent =>Adware.IMBooster
    [HKLM\Software\iSafe] =>Trojan.Staser^

    Malware (10)
    "<--

    Redémarrez le PC

    Ensuite mettez ici les liens :
    du rapport, zhpfix
    d'une nouvelle prise de sang zhpdiag


    Bien cordialement,
    Georges
    Forum :  http://saamu.net/
     Contactez moi  :  http://papynet.mvps.org/MailToMP.htm

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire
  5. Anonyme
    2014-01-24T11:12:25+00:00

    Re

    As ru eu ma derniere réponse concernant le probleme pour installer Hosts ?

    Est ce que je continue tout de meme la suite de la procédure ?

    A  +

    Cette réponse a-t-elle été utile ?

    0 commentaires Aucun commentaire