Tom's Guide > Forum > Sécurité - Virus > VIRUS CID AU SECOUR !!!!!!!!!!!!

VIRUS CID AU SECOUR !!!!!!!!!!!!

Forum Sécurité - Virus : VIRUS CID AU SECOUR !!!!!!!!!!!!

TomsGuide.com : 800 000 inscrits répondent à toutes vos questions high-tech et informatique. Pour obtenir de l'aide, inscrivez-vous gratuitement !
Mot :    Pseudo :           
 

Depuis une semaine je suis ennuyé par le virus CID qui m'ouvre sans arrêt des pages de pubs que dois-je faire pour l'éradiquer??
je précise que j'ai déja vérifier dans ajouter/supprimer des programmes pas de cid xxxx....

merci d'avance

Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Salut,

Télécharge Hijackthis (de Trend Micro)
Poste un rapport en suivant ce tuto.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:39:52, on 23/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aliceadsl.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.aliceadsl.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [CHIN PING PHONE PILE] C:\Documents and Settings\All Users\Application Data\Proxy Long Chin Ping\inside eggs.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [Dash shim] C:\DOCUME~1\ronan\APPLIC~1\WAYDEN~1\vcnounamen.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawfl [...] awflow.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/5 [...] plugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://a516.g.akamai.net/f/516/251 [...] o-eula.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/re [...] oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/s [...] Plugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/onli [...] loader.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: Netiris Agent (Netiris) - Unknown owner - C:\Program Files\Captel\Netiris\agent.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 13240 bytes

Répondre à fabio56

Télécharge Lop S&D.exe ( d’ Eric 71 & Angeldark ) sur ton bureau

  • Double-clique dessus pour lancer l'installation

  • Puis double-clique sur le raccourci Lop S&D présent sur ton bureau

  • Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )

  • Patiente jusqu'à la fin du scan

  • Poste le rapport généré ( C:\lopR.txt )


( Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

+++++++++++++

Télécharge Combofix (de sUBs) sur ton Bureau.

Désactive temporairement toute protection résidente ! (Antivirus, antispywares..)
Double clique combofix.exe.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

Le rapport se trouve ici : C:\Combofix.txt

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

un seul des logiciels fonctionne:


-----------------------------[ Lop S&D 2.1.4 ]---------------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : ronan ] [ "C:\Program Files\Lop SD" ]
[ 2008-01-23 | 22:07:22.43 ] [ PC : SN047290520559 ]
[ MAJ : 23-01-2008 | 21:20 ]

-------------[ Listing des dossiers dans Application Data ]------------

[2008-01-16|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[2008-01-16|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[2007-07-07|16:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2006-11-02|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2007-06-14|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2007-02-01|12:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[2007-08-23|13:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[2004-08-16|17:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2007-01-16|19:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[2007-11-01|16:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EarMaster
[2006-11-18|21:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2007-04-01|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[2007-06-18|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IconTweaker
[2007-05-19|09:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installer.log
[2007-07-06|17:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
[2007-06-18|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogiShrd
[2007-06-18|18:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[2007-09-28|17:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-08-01|18:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2006-11-25|18:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberongames
[2006-11-02|12:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
[2007-12-22|22:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Proxy Long Chin Ping
[2007-06-10|16:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PY_Software
[2007-11-01|19:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2006-12-16|13:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[2004-08-16|18:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[2007-12-23|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skyline
[2006-11-14|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[2008-01-16|21:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-11-13|18:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2007-05-10|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2006-11-02|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[2006-12-14|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WhiteCap (Holiday Edition)
[2006-12-14|18:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2007-12-26|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[2007-12-29|11:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[2006-11-02|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[2006-11-02|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[2004-08-16|17:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2004-08-16|18:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2006-11-02|12:42] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[2004-08-16|17:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2006-11-02|12:43] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[2006-11-02|12:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[2006-11-02|12:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
[2006-11-02|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[2007-12-12|19:11] C:\DOCUME~1\gilles\APPLIC~1\.
[2007-12-12|19:11] C:\DOCUME~1\gilles\APPLIC~1\..
[2008-01-07|08:50] C:\DOCUME~1\gilles\APPLIC~1\Adobe
[2007-05-01|17:26] C:\DOCUME~1\gilles\APPLIC~1\AdobeUM
[2004-08-16|17:55] C:\DOCUME~1\gilles\APPLIC~1\desktop.ini
[2007-08-21|14:27] C:\DOCUME~1\gilles\APPLIC~1\Google
[2007-04-22|10:38] C:\DOCUME~1\gilles\APPLIC~1\ICQ Toolbar
[2004-08-16|18:19] C:\DOCUME~1\gilles\APPLIC~1\Identities
[2006-11-02|12:42] C:\DOCUME~1\gilles\APPLIC~1\Macromedia
[2007-09-24|08:18] C:\DOCUME~1\gilles\APPLIC~1\Microsoft
[2006-11-02|12:43] C:\DOCUME~1\gilles\APPLIC~1\Real
[2007-12-12|19:11] C:\DOCUME~1\gilles\APPLIC~1\Search Settings
[2006-11-02|12:37] C:\DOCUME~1\gilles\APPLIC~1\Sun
[2006-11-02|12:44] C:\DOCUME~1\gilles\APPLIC~1\Symantec
[2006-11-02|12:49] C:\DOCUME~1\gilles\APPLIC~1\You've Got Pictures Screensaver

[2006-11-17|17:43] C:\DOCUME~1\isabelle\APPLIC~1\.
[2006-11-17|17:43] C:\DOCUME~1\isabelle\APPLIC~1\..
[2004-08-16|17:55] C:\DOCUME~1\isabelle\APPLIC~1\desktop.ini
[2004-08-16|18:19] C:\DOCUME~1\isabelle\APPLIC~1\Identities
[2006-11-02|12:42] C:\DOCUME~1\isabelle\APPLIC~1\Macromedia
[2007-05-24|16:58] C:\DOCUME~1\isabelle\APPLIC~1\Microsoft
[2006-11-02|12:43] C:\DOCUME~1\isabelle\APPLIC~1\Real
[2006-11-02|12:37] C:\DOCUME~1\isabelle\APPLIC~1\Sun
[2006-11-02|12:44] C:\DOCUME~1\isabelle\APPLIC~1\Symantec
[2006-11-02|12:49] C:\DOCUME~1\isabelle\APPLIC~1\You've Got Pictures Screensaver

[2004-08-16|18:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[2004-08-16|18:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[2004-08-16|17:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2004-08-16|18:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[2004-08-16|18:18] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[2004-08-16|17:54] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2007-01-20|10:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\.
[2007-01-20|10:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\..
[2007-01-20|10:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\You've Got Pictures Screensaver

[2008-01-22|14:40] C:\DOCUME~1\ronan\APPLIC~1\.
[2008-01-22|14:40] C:\DOCUME~1\ronan\APPLIC~1\..
[2007-12-30|12:37] C:\DOCUME~1\ronan\APPLIC~1\Adobe
[2007-01-24|13:45] C:\DOCUME~1\ronan\APPLIC~1\AdobeUM
[2007-03-28|18:16] C:\DOCUME~1\ronan\APPLIC~1\Ahead
[2008-01-22|14:40] C:\DOCUME~1\ronan\APPLIC~1\Anuman Interactive
[2007-06-14|18:26] C:\DOCUME~1\ronan\APPLIC~1\Apple Computer
[2008-01-13|09:12] C:\DOCUME~1\ronan\APPLIC~1\CoreFTP
[2006-12-14|17:59] C:\DOCUME~1\ronan\APPLIC~1\CyberLink
[2007-12-22|14:01] C:\DOCUME~1\ronan\APPLIC~1\DAEMON Tools
[2004-08-16|17:55] C:\DOCUME~1\ronan\APPLIC~1\desktop.ini
[2007-11-01|16:19] C:\DOCUME~1\ronan\APPLIC~1\EarMaster
[2007-06-02|11:40] C:\DOCUME~1\ronan\APPLIC~1\EoRezo
[2006-11-16|20:24] C:\DOCUME~1\ronan\APPLIC~1\FotoWire
[2007-03-10|21:54] C:\DOCUME~1\ronan\APPLIC~1\Google
[2007-10-18|19:06] C:\DOCUME~1\ronan\APPLIC~1\iBloks
[2007-05-26|11:45] C:\DOCUME~1\ronan\APPLIC~1\ICAClient
[2007-06-18|18:30] C:\DOCUME~1\ronan\APPLIC~1\IconTweaker
[2007-04-22|10:22] C:\DOCUME~1\ronan\APPLIC~1\ICQ Toolbar
[2004-08-16|18:19] C:\DOCUME~1\ronan\APPLIC~1\Identities
[2007-06-30|13:42] C:\DOCUME~1\ronan\APPLIC~1\Inkscape
[2008-01-18|14:23] C:\DOCUME~1\ronan\APPLIC~1\InstallShield
[2007-06-02|11:37] C:\DOCUME~1\ronan\APPLIC~1\ItsLabel
[2007-01-11|20:33] C:\DOCUME~1\ronan\APPLIC~1\Leadertech
[2007-06-16|16:39] C:\DOCUME~1\ronan\APPLIC~1\Macromedia
[2007-09-11|17:33] C:\DOCUME~1\ronan\APPLIC~1\Microsoft
[2007-09-01|17:45] C:\DOCUME~1\ronan\APPLIC~1\Mozilla
[2007-03-03|15:32] C:\DOCUME~1\ronan\APPLIC~1\MtStudio
[2008-01-12|22:19] C:\DOCUME~1\ronan\APPLIC~1\Nvu
[2006-11-15|18:01] C:\DOCUME~1\ronan\APPLIC~1\OD2
[2008-01-23|17:01] C:\DOCUME~1\ronan\APPLIC~1\OpenOffice.org2
[2006-11-16|18:02] C:\DOCUME~1\ronan\APPLIC~1\Real
[2007-12-04|19:23] C:\DOCUME~1\ronan\APPLIC~1\Search Settings
[2007-09-01|18:02] C:\DOCUME~1\ronan\APPLIC~1\SecondLife
[2007-12-22|22:50] C:\DOCUME~1\ronan\APPLIC~1\Sibelius Software
[2006-11-14|19:29] C:\DOCUME~1\ronan\APPLIC~1\Skype
[2007-01-11|20:36] C:\DOCUME~1\ronan\APPLIC~1\Sonic
[2006-11-02|12:37] C:\DOCUME~1\ronan\APPLIC~1\Sun
[2006-11-02|12:44] C:\DOCUME~1\ronan\APPLIC~1\Symantec
[2006-11-23|20:49] C:\DOCUME~1\ronan\APPLIC~1\Template
[2007-12-19|20:13] C:\DOCUME~1\ronan\APPLIC~1\uk.co.planetside
[2007-12-11|17:55] C:\DOCUME~1\ronan\APPLIC~1\Viewpoint
[2007-06-26|12:08] C:\DOCUME~1\ronan\APPLIC~1\ViStart
[2007-06-26|12:43] C:\DOCUME~1\ronan\APPLIC~1\vlc
[2007-12-26|14:16] C:\DOCUME~1\ronan\APPLIC~1\waydentcity
[2008-01-19|15:09] C:\DOCUME~1\ronan\APPLIC~1\wklnhst.dat
[2006-11-02|12:49] C:\DOCUME~1\ronan\APPLIC~1\You've Got Pictures Screensaver

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[2008-01-18 15:09][--a------] C:\WINDOWS\tasks\Norton Security Scan.job [--408--]
[2008-01-23 22:00][--ah-----] C:\WINDOWS\tasks\A8522F5E90F1AB62.job [--262--]
[2008-01-23 09:31][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{D19A44CD-F625-45DB-A8D9-EF716BB694A9}.job [--422--]
[2008-01-23 19:30][--a------] C:\WINDOWS\tasks\Configurer mon PC.job [--244--]
[2008-01-23 17:00][--ah-----] C:\WINDOWS\tasks\SA.DAT [--6--]
[2004-08-05 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini [--65--]

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[2008-01-23|22:07] C:\Program Files\Lop SD
[2008-01-23|21:58] C:\Program Files\..
[2008-01-23|21:58] C:\Program Files\.
[2008-01-23|20:38] C:\Program Files\Trend Micro
[2008-01-23|17:10] C:\Program Files\Messenger Plus! Live
[2008-01-22|14:48] C:\Program Files\LiveCAD
[2008-01-20|19:29] C:\Program Files\Dict‚e et M‚moire Musicale [DEMO]
[2008-01-20|15:56] C:\Program Files\M‚thode de Guitare - DEMO Volume I
[2008-01-20|10:53] C:\Program Files\IKEA HomePlanner
[2008-01-20|10:04] C:\Program Files\home plan software
[2008-01-20|09:59] C:\Program Files\Fichiers communs
[2008-01-18|15:00] C:\Program Files\Norton Security Scan
[2008-01-18|14:37] C:\Program Files\WarRock
[2008-01-18|14:23] C:\Program Files\InstallShield Installation Information
[2008-01-18|12:14] C:\Program Files\RomuSoft
[2008-01-16|20:29] C:\Program Files\Microsoft FrontPage Express
[2008-01-16|19:49] C:\Program Files\Spybot - Search & Destroy
[2008-01-13|12:51] C:\Program Files\BoontyGames
[2008-01-13|12:51] C:\Program Files\Boonty
[2008-01-13|09:11] C:\Program Files\CoreFTP
[2008-01-12|22:45] C:\Program Files\Amaya
[2008-01-12|22:19] C:\Program Files\Nvu
[2008-01-12|22:18] C:\Program Files\Ma‹do Production
[2007-12-26|14:03] C:\Program Files\CCleaner
[2007-12-23|11:08] C:\Program Files\CyberLink
[2007-12-23|11:00] C:\Program Files\Steam
[2007-12-23|10:56] C:\Program Files\Google
[2007-12-23|10:55] C:\Program Files\Anuman Interactive
[2007-12-23|10:54] C:\Program Files\Cadsoft
[2007-12-22|22:23] C:\Program Files\waydentcity
[2007-12-12|20:47] C:\Program Files\Internet Explorer
[2007-12-04|19:22] C:\Program Files\Search Settings
[2007-11-18|19:26] C:\Program Files\CTV PROD
[2007-11-05|18:45] C:\Program Files\Picasa2
[2007-11-03|09:31] C:\Program Files\yatching virtual
[2007-11-01|19:48] C:\Program Files\EarMaster School 5
[2007-11-01|16:19] C:\Program Files\EarMaster Pro 5
[2007-10-18|19:04] C:\Program Files\MSBuild
[2007-10-18|19:00] C:\Program Files\Reference Assemblies
[2007-10-18|18:43] C:\Program Files\VstPlugins
[2007-10-08|17:31] C:\Program Files\Java
[2007-08-29|16:54] C:\Program Files\Logitech
[2007-08-14|19:12] C:\Program Files\MSXML 4.0
[2007-07-07|16:58] C:\Program Files\Adobe
[2007-07-05|17:05] C:\Program Files\directx
[2007-07-05|17:00] C:\Program Files\Micro Application
[2007-06-30|16:52] C:\Program Files\Sailcut CAD
[2007-06-26|13:04] C:\Program Files\Windows Media Player
[2007-06-16|16:44] C:\Program Files\QuickTime
[2007-06-15|17:46] C:\Program Files\icones
[2007-06-14|20:25] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2007-06-14|20:25] C:\Program Files\Outlook Express
[2007-06-14|20:10] C:\Program Files\Apple Software Update
[2007-06-14|20:10] C:\Program Files\Apple Software Update(2)
[2007-06-14|19:57] C:\Program Files\Windows Live
[2007-06-10|16:39] C:\Program Files\Bible
[2007-06-10|16:36] C:\Program Files\Captel
[2007-06-10|10:39] C:\Program Files\Web Media Player
[2007-06-10|09:55] C:\Program Files\BOINC
[2007-06-10|08:58] C:\Program Files\Mlehrer
[2007-06-02|14:16] C:\Program Files\NetMeeting
[2007-06-02|11:40] C:\Program Files\eoRezo
[2007-06-02|10:20] C:\Program Files\Movie Maker
[2007-05-21|18:07] C:\Program Files\Alice
[2007-05-19|11:08] C:\Program Files\ffdshow
[2007-05-12|10:26] C:\Program Files\Guitar Pro 5
[2007-05-09|18:55] C:\Program Files\Stardock
[2007-02-10|17:47] C:\Program Files\ISOpen
[2007-02-08|18:04] C:\Program Files\Audacity
[2007-01-30|14:48] C:\Program Files\OpenOffice.org 2.1
[2007-01-15|18:09] C:\Program Files\Dynamic Toolbar
[2006-12-14|18:53] C:\Program Files\Windows Media Connect 2
[2006-11-14|18:20] C:\Program Files\HP
[2006-11-13|18:23] C:\Program Files\Alwil Software
[2006-11-02|12:53] C:\Program Files\Sonic
[2006-11-02|12:52] C:\Program Files\Microsoft Office
[2006-11-02|12:52] C:\Program Files\Microsoft.NET
[2006-11-02|12:51] C:\Program Files\Microsoft Works
[2006-11-02|12:43] C:\Program Files\Real
[2006-11-02|12:34] C:\Program Files\Realtek Sound Manager
[2004-08-16|18:19] C:\Program Files\Uninstall Information
[2004-08-16|18:11] C:\Program Files\microsoft frontpage
[2004-08-16|18:11] C:\Program Files\xerox
[2004-08-16|18:07] C:\Program Files\WindowsUpdate
[2004-08-16|18:03] C:\Program Files\Online Services
[2004-08-16|18:03] C:\Program Files\Messenger
[2004-08-16|18:03] C:\Program Files\MSN Gaming Zone
[2004-08-16|18:03] C:\Program Files\Windows NT
[2004-07-22|10:51] C:\Program Files\ManagedDX.CAB
[2004-07-19|22:58] C:\Program Files\BDANT.cab
[2004-07-19|22:53] C:\Program Files\BDAXP.cab
[2004-07-09|14:17] C:\Program Files\dxnt.cab
[2004-07-09|09:13] C:\Program Files\DirectX.cab
[2004-07-09|09:13] C:\Program Files\BDA.cab
[2004-07-09|04:08] C:\Program Files\dxsetup.exe
[2004-07-09|04:08] C:\Program Files\dsetup32.dll
[2004-07-09|03:03] C:\Program Files\DSETUP.dll

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[2008-01-20|09:59] C:\Program Files\Fichiers communs\..
[2008-01-20|09:59] C:\Program Files\Fichiers communs\Wise Installation Wizard
[2008-01-20|09:59] C:\Program Files\Fichiers communs\.
[2008-01-20|09:42] C:\Program Files\Fichiers communs\Symantec Shared
[2007-12-19|20:14] C:\Program Files\Fichiers communs\InstallShield
[2007-12-08|19:55] C:\Program Files\Fichiers communs\Microsoft Shared
[2007-12-08|19:54] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2007-11-30|16:07] C:\Program Files\Fichiers communs\Totem Shared
[2007-08-29|16:54] C:\Program Files\Fichiers communs\LogiShrd
[2007-07-07|16:58] C:\Program Files\Fichiers communs\Adobe
[2007-06-14|20:25] C:\Program Files\Fichiers communs\System
[2007-06-14|20:10] C:\Program Files\Fichiers communs\GTK
[2007-04-16|17:26] C:\Program Files\Fichiers communs\Logitech
[2007-04-16|17:03] C:\Program Files\Fichiers communs\Java
[2007-03-23|17:55] C:\Program Files\Fichiers communs\SWF Studio
[2007-03-15|19:40] C:\Program Files\Fichiers communs\MimarSinan
[2007-02-01|12:59] C:\Program Files\Fichiers communs\BOONTY Shared
[2006-11-16|20:24] C:\Program Files\Fichiers communs\FotoWire
[2006-11-14|18:16] C:\Program Files\Fichiers communs\Hewlett-Packard
[2006-11-02|12:53] C:\Program Files\Fichiers communs\Sonic Shared
[2006-11-02|12:52] C:\Program Files\Fichiers communs\DESIGNER
[2006-11-02|12:49] C:\Program Files\Fichiers communs\AOL
[2006-11-02|12:49] C:\Program Files\Fichiers communs\aolshare
[2006-11-02|12:49] C:\Program Files\Fichiers communs\Nullsoft
[2006-11-02|12:43] C:\Program Files\Fichiers communs\xing shared
[2006-11-02|12:43] C:\Program Files\Fichiers communs\Real
[2006-11-02|12:42] C:\Program Files\Fichiers communs\SureThing Shared
[2004-08-16|18:06] C:\Program Files\Fichiers communs\Services
[2004-08-16|18:06] C:\Program Files\Fichiers communs\MSSoap
[2004-08-16|17:57] C:\Program Files\Fichiers communs\ODBC
[2004-08-16|17:56] C:\Program Files\Fichiers communs\SpeechEngines

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Proxy Long Chin Ping
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Proxy Long Chin Ping\inside eggs.exe
C:\WINDOWS\Tasks\A8522F5E90F1AB62.job

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHIN PING PHONE PILE"="C:\\Documents and Settings\\All Users\\Application Data\\Proxy Long Chin Ping\\inside eggs.exe"

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts MODIFIE

127.0.0.1 localhost
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 22:08:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
scan completed successfully
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:320][Doss:24] C:\DOCUME~1\ronan\LOCALS~1\Temp
/!\ [Fich:165][Doss:0] C:\DOCUME~1\ronan\Cookies
/!\ [Fich:2314][Doss:6] C:\DOCUME~1\ronan\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 22:08:30.35 ]----------------------

Répondre à fabio56

Re,

Pas mal de choses à faire .. !

1/ Relance Lop S&D

  • Choisis cette fois ci l'Option 2 ( Suppression )

  • Ne ferme pas la fenêtre lors de la suppression !

  • Poste le rapport généré ( C:\lopR.txt )


( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

2/ Télécharge Navilog (de Il-Mafioso)

Enregistre-le sur ton Bureau.
Installe-le en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

Une fois l'installation terminée, fais un clic droit sur le raccourci navilog1 puis choisis "Exécuter en tant qu'administrateur". ( Pour Vista)

Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
! N'utilise pas l'option 2,3 et 4 sans notre accord !
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste le rapport ici.

Le rapport se trouve ici :C:\fixnavi.txt

3/ Télécharge et exécute cet utilitaire :
http://service1.symantec.com/SUPPO [...] 4110429924

4/ Désinstalle :
- Boonty
- Eoreozo


Télécharge OTMoveIt > Tuto <

Sauvegarde-le sur le Bureau

Séléctionne l'encadré ci-dessous

C:\Program Files\Fichiers communs\BOONTY Shared
C:\Program Files\eoRezo
C:\Program Files\BoontyGames
C:\DOCUME~1\ronan\APPLIC~1\Viewpoint
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY


Lance maintenant OTMoveIt .
Assure toi que la case unregister dll’s and ocx’s soit cochée.
Deux cadres apparaissent , clique droit sur le cadre de gauche , puis colle l'encadré ci desssus.
Et clique sur Movelt !

Si le programme te demande de redemarrer, accepte.

Poste le rapport qui se trouve dans : C:\_OTMoveIt\MovedFiles\date de création!

NOTE : Si tu obtiens un message comme quoi le rapport ne peut pas être créé, copie/colle ce qui apparaît dans la colonne droite de l’outil.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX
Tom's Guide > Forum > Sécurité - Virus > VIRUS CID AU SECOUR !!!!!!!!!!!!
Aller à :

Il y a 557 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens