salut
Je te remercie bcp ca a marche beamrise a l'air d'etre detruit MAIS il n'etait pas venu seul! Il y a d'autres logiciels tel que FTdownloader, pinterest et facebook qui sont restes...pareil le meme phenomene avec des icones sans logos. Qu'est-ce qu'il y a a faire?
Je te donne le rapport
¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module | g3n-h@ckm@n | 24.02.2014.5
¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 22:32:35 - 24/02/2014
update on : 24/02/2014 | 14.00 by g3n-h@ckm@n
Contact :
http://www.sosvirus.net
Boot : Normal
System : Microsoft Windows XP (32 bits) Service Pack 3
RAM memory = Total (MB) : 1039 | Free (MB) : 388
Pagefile = Total (MB) : 2500 | Free (MB) : 1937
Virtual = Total (MB) : 2097 | Free (MB) : 2018
Registry saved, to restore : C:\Shortcut_Module\Save\Clean\ERDNT.exe
¤¤¤¤¤¤¤¤¤¤ | Windows Updates
Last détection : 2014-02-24 21:18:01
Last downloaded : 2014-02-24 21:17:57
Last installation : 2014-02-14 14:03:17
Next search : 2014-02-25 15:36:40
¤¤¤¤¤¤¤¤¤¤ | Killed processes
1904 | C:\WINDOWS\system32\spoolsv.exe (.Microsoft Corporation - Spooler SubSystem App.) - (5.1.2600.6024) - C:\WINDOWS\system32\spoolsv.exe
200 | C:\WINDOWS\Explorer.EXE (.Microsoft Corporation - Windows Explorer.) - (6.0.2900.5512) - C:\WINDOWS\Explorer.EXE
848 | C:\WINDOWS\stsystra.exe (.SigmaTel, Inc. - Sigmatel Audio system tray application.) - (1.0.4995.1) - "C:\WINDOWS\stsystra.exe"
864 | C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) - (8.2.4.3) - "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
436 | C:\WINDOWS\system32\igfxtray.exe (.Intel Corporation - igfxTray Module.) - (6.14.10.4926) - "C:\WINDOWS\system32\igfxtray.exe"
876 | C:\WINDOWS\system32\hkcmd.exe (.Intel Corporation - hkcmd Module.) - (6.14.10.4926) - "C:\WINDOWS\system32\hkcmd.exe"
888 | C:\WINDOWS\system32\igfxpers.exe (.Intel Corporation - persistence Module.) - (6.14.10.4926) - "C:\WINDOWS\system32\igfxpers.exe"
1160 | C:\WINDOWS\system32\igfxsrvc.exe (.Intel Corporation - igfxsrvc Module.) - (6.14.10.4926) - C:\WINDOWS\system32\igfxsrvc.exe -Embedding
1360 | C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) - (1.7.4.0) - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
1452 | C:\WINDOWS\system32\ctfmon.exe (.Microsoft Corporation - CTF Loader.) - (5.1.2600.5512) - "C:\WINDOWS\system32\ctfmon.exe"
2092 | C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (.Apple Inc. - Apple Mobile Device Service.) - (16.57.0.11) - "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
2108 | C:\Program Files\Bonjour\mDNSResponder.exe (.Apple Inc. - Bonjour Service.) - (2.0.1.2) - "C:\Program Files\Bonjour\mDNSResponder.exe"
2532 | C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - (1.70.0.0) - "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe"
3076 | C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - (1.70.0.0) - "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
2408 | C:\Program Files\Internet Explorer\iexplore.exe (.Microsoft Corporation - Internet Explorer.) - (8.0.6001.18702) - "C:\Program Files\Internet Explorer\iexplore.exe"
3224 | C:\Program Files\Internet Explorer\iexplore.exe (.Microsoft Corporation - Internet Explorer.) - (8.0.6001.18702) - "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2408 CREDAT:79873
2620 | C:\WINDOWS\system32\wuauclt.exe (.Microsoft Corporation - Windows Update.) - (7.6.7600.256) - "C:\WINDOWS\system32\wuauclt.exe"
2724 | C:\Program Files\Internet Explorer\iexplore.exe (.Microsoft Corporation - Internet Explorer.) - (8.0.6001.18702) - "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2408 CREDAT:14344
1516 | C:\WINDOWS\system32\wscntfy.exe (.Microsoft Corporation - Windows Security Center Notification App.) - (5.1.2600.5512) - C:\WINDOWS\system32\wscntfy.exe
¤¤¤¤¤¤¤¤¤¤ | Running processes
[04/08/2004 11:00:00] - 812 | C:\WINDOWS\System32\smss.exe (.Microsoft Corporation - Windows NT Session Manager.) - (5.1.2600.5512) - \SystemRoot\System32\smss.exe [50688 Ko]
[04/08/2004 11:00:00] - 932 | C:\WINDOWS\system32\winlogon.exe (.Microsoft Corporation - Windows NT Logon Application.) - (5.1.2600.5512) - winlogon.exe [507904 Ko]
[04/08/2004 11:00:00] - 976 | C:\WINDOWS\system32\services.exe (.Microsoft Corporation - Services and Controller app.) - (5.1.2600.5755) - C:\WINDOWS\system32\services.exe [110592 Ko]
[04/08/2004 11:00:00] - 988 | C:\WINDOWS\system32\lsass.exe (.Microsoft Corporation - LSA Shell (Export Version).) - (5.1.2600.5512) - C:\WINDOWS\system32\lsass.exe [13312 Ko]
[04/08/2004 11:00:00] - 1152 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) - C:\WINDOWS\system32\svchost -k DcomLaunch [14336 Ko]
[04/08/2004 11:00:00] - 1260 | C:\WINDOWS\System32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) - C:\WINDOWS\System32\svchost.exe -k netsvcs [14336 Ko]
[26/04/2010 11:11:24] - 1768 | C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (.AVAST Software - avast! Service.) - (7.0.1466.549) - "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [44808 Ko]
[26/04/2010 11:11:24] - 1368 | C:\Program Files\Alwil Software\Avast5\avastUI.exe (.AVAST Software - avast! Antivirus.) - (7.0.1466.549) - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui [4282728 Ko]
[23/02/2014 14:01:04] - 2712 | C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - (1.70.0.0) - "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [701512 Ko]
[04/08/2004 11:00:00] - 2828 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) - C:\WINDOWS\system32\svchost.exe -k imgsvc [14336 Ko]
[23/04/2010 22:29:44] - 2724 | C:\Program Files\Internet Explorer\iexplore.exe (.Microsoft Corporation - Internet Explorer.) - (8.0.6001.18702) - "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2408 CREDAT:14344 [638816 Ko]
[24/02/2014 22:30:57] - 3732 | C:\Documents and Settings\Clement\Local Settings\Temporary Internet Files\Content.IE5\RV3Q0L07\Shortcut_Module[1].exe (. - Shortcut_Module.) - (24.2.2014.5) - "C:\Documents and Settings\Clement\Local Settings\Temporary Internet Files\Content.IE5\RV3Q0L07\Shortcut_Module[1].exe" [2136576 Ko]
¤¤¤¤¤¤¤¤¤¤ | Services
¤¤¤¤¤¤¤¤¤¤ | Hosts
C:\WINDOWS\System32\Drivers\etc\hosts : Reseted successfully
¤¤¤¤¤¤¤¤¤¤ | Register
Deleted successfully : HKLM\Software\Classes\AMtoolbar.AMtoolbar
Deleted successfully : HKLM\Software\Classes\AMtoolbar.AMtoolbar.1
Deleted successfully : HKLM\Software\Classes\protector_dll.Protector
Deleted successfully : HKLM\Software\Classes\protector_dll.Protector.1
Deleted successfully : HKLM\Software\Classes\protector_dll.ProtectorLib.1
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.CoCreateAsync
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.CoreMachineClass
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.CoreMachineClass.1
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.CredentialDialogMachine.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.OnDemandCOMClassMachineFallback.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.OnDemandCOMClassSvc.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.ProcessLauncher.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3COMClassService.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3WebMachine.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3WebMachineFallback.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3WebSvc.1.0
Deleted successfully : HKLM\Software\Classes\protector_dll.ProtectorLib
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.CoCreateAsync.1.0
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.OnDemandCOMClassMachineFallback
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.ProcessLauncher
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3WebMachine
Deleted successfully : HKLM\Software\Classes\SoftwareUpdate.Update3WebSvc
Deleted successfully : HKLM\Software\Classes\AppID\{6A070EEA-E3F8-411E-9D3A-F3814ED6D1A8} : SoftwareUpdateApp
Deleted successfully : HKLM\Software\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D} : protector_dll
Deleted successfully : HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Beamrise
Deleted successfully : HKLM\Software\Classes\Installer\Products\0DC1503A46F231838AD88BCDDC8E8F7C : C:\DOCUME~1\Clement\LOCALS~1\Temp\dotnetfx3530729.01\1033\dotnetfx30\
Deleted successfully : HKLM\Software\Classes\Installer\Products\26DDC2EC4210AC63483DF9D4FCC5B59D : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP05C65.tmp\dotnetfx35\x86\
Deleted successfully : HKLM\Software\Classes\Installer\Products\30EB1ED92EFABDC4FBBE0DD637C60DA1 : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP255.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\54A306F2659DB694185B057D28249467 : C:\DOCUME~1\Clement\LOCALS~1\Temp\{BE28F43F-3677-4982-830C-5FFCA513F05D}\
Deleted successfully : HKLM\Software\Classes\Installer\Products\8F021BF4C2260624BA94F0345AC9FCA2 : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP255.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\926352A811504584B8E4645EE76600C5 : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP255.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\9B00314CD581E574FBCE93FE37F2911B : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP255.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\DC3BF90CC0D3D2F398A9A6D1762F70F3 : C:\DOCUME~1\Clement\LOCALS~1\Temp\dotnetfx3530729.01\1033\dotnetfx20\
Deleted successfully : HKLM\Software\Classes\Installer\Products\E603EB826AD5C9F4DB0BBD3A8C6CFFDF : C:\DOCUME~1\Clement\LOCALS~1\Temp\IXP255.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\2BC4C58B253B8DB418C8CB3E35951970 : C:\DOCUME~1\Clement\LOCALS~1\Temp\{DD757888-8A11-4760-B230-EF12C81D60C3}\
Deleted successfully : HKLM\Software\Classes\Installer\Products\5C1093C35543A0E32A41B090A305076A : C:\DOCUME~1\Clement\LOCALS~1\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\
Deleted successfully : HKLM\Software\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a : C:\WINDOWS\TEMP\IXP000.TMP\
Deleted successfully : HKLM\Software\Classes\Installer\Products\FCDAC0A0AD874C333A05DC1548B97920 : C:\DOCUME~1\Clement\LOCALS~1\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\
Deleted successfully : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] : C:\Program Files\SweetIM\Messenger\msvcr71.dll
Deleted successfully : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\24D4E9A30476A184E9FBAF8014095AAA] : C:\DOCUME~1\Clement\LOCALS~1\Temp\SetupDataMngr_iMesh.exe
Deleted successfully : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] : C:\Program Files\SweetIM\Messenger\msvcp71.dll
Deleted successfully : [HKLM\Software\Microsoft\Command Processor]|[AutoRun] :
Deleted successfully : [HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run]|[swg] : "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
¤¤¤¤¤¤¤¤¤¤ | IFEO
¤¤¤¤¤¤¤¤¤¤ | Folders
Deleted successfully : C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
Deleted successfully : C:\Documents and Settings\Clement\Desktop\Beamrise Photobooth.lnk
Deleted successfully : C:\Documents and Settings\Clement\Desktop\Beamrise Videochat.lnk
Deleted successfully : C:\Documents and Settings\Clement\Desktop\Beamrise.lnk
Deleted successfully : C:\Documents and Settings\Clement\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\3372725252.data
Deleted successfully : C:\Documents and Settings\Clement\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\3372725252.quar
¤¤¤¤¤¤¤¤¤¤ | Hijack.Shortcut
Disinfected : C:\Documents and Settings\Clement\Desktop\Pinterest.lnk : C:\Documents and Settings\Clement\Local Settings\Application Data\Beamrise\Application\beamrise.exe (hxxp://search2.beamrise.com/pinterest)
¤¤¤¤¤¤¤¤¤¤ | Hijack.Internet Explorer
Repaired : [HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
https://www.google.fr/ -
http://www.google.com/
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Search]|[SearchAssistant] :
http://www.google.com -
http://www.google.com/ie
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://www.google.com -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://www.google.com -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\PhishingFilter]|[Enabled] : 1 - 2
Repaired : [HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\PhishingFilter]|[EnabledV8] : 0 - 1
Repaired : [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 - 1
Repaired : [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 - 1
Repaired : [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 - 1
Repaired : [HKU\S-1-5-21-1085031214-1390067357-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
¤¤¤¤¤¤¤¤¤¤ | Hijack.Google Chrome
¤¤¤¤¤¤¤¤¤¤ | Hijack.Firefox
¤¤¤¤¤¤¤¤¤¤ | Hijack.StartMenuInternet
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : iexplore.exe - "C:\Program Files\Internet Explorer\iexplore.exe"
¤¤¤¤¤¤¤¤¤¤ | AppInit_DLLs
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 1
¤¤¤¤¤¤¤¤¤¤ | Hijack.Javascript
¤¤¤¤¤¤¤¤¤¤ | Firewall
¤¤¤¤¤¤¤¤¤¤ | Temporary files
[All Users] Temporary files deleted : 0 Ko
[Default User] Temporary files deleted : 0 Ko
[NetworkService] Temporary files deleted : 0 Ko
[LocalService] Temporary files deleted : 0 Ko
[Clement] Temporary files deleted : 0 Ko
¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤ | 22:37:19