Home > General > TrojanDNSchanger.hg

TrojanDNSchanger.hg

Et scanne complet ! 1 Nouveau sujetListe des sujets Actualiser Répondre Prévisu Stickers ? Je redémarre en mode normal, relance le scan et là plus rien d'anormal. I cannot even run disk cleanup without a windows error please help ! We should be finished then.

Back to top #13 meater meater Member Full Member 12 posts Posted 23 January 2007 - 05:48 PM reg search log : REGEDIT4; RegSrch.vbs Bill James; Registry search results for jedi jedi My help is free, but if you wish to help keep these forums running please consider a donation, see This Topic for details. HKLM\System\CCS\Services\Tcpip\..\{2F1A6493-4B90-4604-B862-C70FB5547536}: NameServer = 85.255.115.114,85.255.112.142 Il faut déjà avec Hijackthis cocher toutes ces entrées O17 et faire fixed pour tous les éliminer. C:\Documents and Settings\Thierry\Local Settings\Temp\Cookies\[email protected]​sexlist[2].txt -> TrackingCookie.Sexlist : Nettoyé.

Cela va créer un dossier clean. Double click combofix.exe & follow the prompts.3. Double-clic sur clean. Search five digit cs, dm, kd, jb, other, files.

C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christin​[email protected][1].txt -> TrackingCookie.Starware : Nettoyé. It's harmless. Post that log in your next replyNote: Do not mouseclick combofix's window whilst it's running. C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christin​[email protected][1].txt -> TrackingCookie.2o7 : Nettoyé.

Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)O2 - BHO: (no Mon PC est infecté par Trojan.DnsChanger et je n'arrive pas à m'en débarrasser. Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [KernelFaultCheck] Pour faire entendre notre voix, nous devons être le plus nombreux possibles, alors rapport ton infection : - Voir les règles de Malware-Complaints - Enregistre sur le forum à partir du

C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christin​[email protected][1].txt -> TrackingCookie.Overture : Nettoyé. This is only a short scan.Once the short scan has finished, mark the drives that you want to scan. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»» Searching by size/names... »»»»» Search five digit cs, dm kd and jb files.This WILL/CAN also list Legit Files, Submit C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christin​[email protected][2].txt -> TrackingCookie.Adtech : Nettoyé.

poste le rapport!

carameletc​hocolat Posté le 21/01/2007à20:59:02 J'ai suivi les instructions mais il semble que Bitdefender online en ait pour au minimum 15 heures à scanner le PC (avg a mis http://www.geekstogo.com/forum/topic/148508-trojandnschangerhg/ Inscription superflue (car sans effet) qui peut donc être effacée ! It does not count as help. HKLM\System\CCS\Services\Tcpip\..\{2F1A6493-4B90-4604-B862-C70FB5547536}: NameServer = 85.255.115.114,85.255.112.142 Ok, et je corrige ça comment? (Je suis chez Free, ADSL avec FreeBox HD) Message édité par Niko_ka le 27-12-2006à15:09:10dnlilasPosté le 27-12-2006à15:17:11Il faut que tu lances Hijackthis,

Back to top #14 meater meater Member Full Member 12 posts Posted 24 January 2007 - 09:46 AM if anything else can be removed that isn't needed let me know cheers!! A red dot shows which drives have been chosen.Click the green arrow at the right, and the scan will start. C:\Documents and Settings\Thierry\Local Settings\Temp\Cookies\[email protected]​tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Nettoyé. Double click combofix.exe & follow the prompts.3.

Click 'Yes to all' if it asks if you want to cure/move the file.When the scan has finished, look if you can click next icon next to the files found: If hijackthis log :Logfile of HijackThis v1.99.1Scan saved at 14:29:25, on 16/01/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Spyware Doctor\sdhelp.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\Program Files\PokerOffice\bin\javaw.exeC:\Program Files\Common Files\Teleca Shared\Generic.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\The3Dpoker\The3Dpoker.exeC:\Program Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier. Join the community!

Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)O2 - BHO: (no If you are sure you do not need a specific DNS address here, you may proceed.Double-click the Network Connections iconRight-click the Local Area Connection icon and select Properties.Hilight Internet Protocol (TCP/IP)

Malheureusement, Trojan.DnsChanger était toujours là et de plus j'avais pas mal de tracking Cookies.

Create Account How it Works Javascript Disabled Detected You currently have javascript disabled. C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christin​[email protected][1].txt -> TrackingCookie.Serving-sys : Nettoyé. Enter this item into that field (copy and paste): COM+ Messages Click OK.It should pull up information about the service, when it asks if you want to reboot now click YESPlease C:\Documents and Settings\Thierry\Local Settings\Temp\Cookies\[email protected]​estat[1].txt -> TrackingCookie.Estat : Nettoyé.

If you need this topic reopened, please contact a staff member. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy nos newsletters Back to top #9 meater meater Member Full Member 12 posts Posted 22 January 2007 - 04:32 PM combofix log : "sweet" - 07-01-22 21:28:08 Service Pack 2ComboFix 07-01-21 - Running C:\Documents and Settings\Thierry\Local Settings\Temp\Temporary Internet Files\Content.IE5\CXAN0LAV\exp​2[1].htm -> Downloader.Agent.bx : Nettoyé.