Tom's Guide > Forum > Sécurité - Virus > Mon pc ram !!! il ne veu plus rien faire

Mon pc ram !!! il ne veu plus rien faire

Forum Sécurité - Virus : Mon pc ram !!! il ne veu plus rien faire

TomsGuide.com : 800 000 inscrits répondent à toutes vos questions high-tech et informatique. Pour obtenir de l'aide, inscrivez-vous gratuitement !
Mot :    Pseudo :           
 

Bonjour, voila mon pc ram grave, il ne veut plus rien faire au bout de 30 min, 1h00 et ma box s'éteind assez souvent dans la journée quand on navigue sur le net ...

voila j'aimerais avoir de l'aide !!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:26:38, on 22/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Fichiers communs\AOL\1195902532\ee\AOLSoftware.exe
C:\Program Files\TOPRO\TPPOLL.EXE
C:\WINDOWS\OV530EM.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ViiincEnt\Bureau\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc [...] 0c&Ext=tdc
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,C:\WINDOWS\system32\i386kd.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1195902532\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [TPPOLL] C:\Program Files\TOPRO\TPPOLL.EXE
O4 - HKLM\..\Run: [Ovt Wia] C:\WINDOWS\OV530EM.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Defy Inside Proc Heart] C:\Documents and Settings\All Users\Application Data\burn download defy inside\Audio multi.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Itch ford four knob] C:\Documents and Settings\All Users\Application Data\third lies itch ford\Ace Media.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [help amok] C:\DOCUME~1\VIIINC~1\APPLIC~1\ONLINE~1\4styledash.exe
O4 - HKCU\..\Run: [EasyFlirt Messenger] C:\Program Files\EasyFlirt Messenger\EasyFlirt Messenger.exe /M
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Compagnon.lnk = C:\Program Files\AOL Compagnon\companion.exe
O4 - Global Startup: Lancer l'utilitaire d'enregistrement.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://xel-chicox.spaces.live.com/ [...] nPUpld.cab
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/con [...] Helper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Games [...] meHost.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://jeuxenligne.orange.fr/GameS [...] der_v6.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - c:\xampp\FileZillaFTP\FileZillaServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 14795 bytes

Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Salut,

Télécharge SDFix (d’Andy Manchesta)

Enregistre le sur ton le bureau.

Lance le.
Fais install afin qu’il puisse s’extraire.

Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

Lance SDFix.
Double clique sur RunThis.bat . (L’extension bat peut ne pas apparaître)
Appuie sur Y pour le lancer.

Il te sera demandé d'appuyer sur une touche pour redemarrer , fais le
Il est probable que le redémarrage soit un peu plus long que d’habitude.
Une fois l’apparition de ton Bureau, il affichera Finished

Appuie sur une touche.

Un rapport est généré , poste le dans ta réponse.
Il se trouve également. dans le dossier SDFix >Report.txt<

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

Désoler du retard !!!

Voila le rapport SDFix !! :::




SDFix: Version 1.145

Run by HP_Administrateur on 05/03/2008 at 16:01

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name:
FCI
khtml

Path:
C:\WINDOWS\system32\svchost.exe:ext.exe
\??\C:\WINDOWS\system32\drivers\khtml.sys

FCI - Deleted
khtml - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting

Service Ujfk36 - Deleted after Reboot

Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\drivers\Ujfk36.sys - Deleted
C:\-38848~1 - Deleted
C:\Documents and Settings\HP_Administrateur\Local Settings\Temp\aax221.tmp.exe - Deleted
C:\Program Files\Helper\1201459562.dll - Deleted
C:\WINDOWS\system32\drivers\khtml.sys - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted



Folder C:\Program Files\Helper - Removed
Folder C:\WINDOWS\system32\wsnpoem - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-05 16:23:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:1e,e1,6b,79,01,79,86,81,ff,cc,c8,41,0f,e1,51,2e,d3,ba,a5,ee,9a,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00

000001]
"a0"=hex:20,01,00,00,9d,be,84,14,7a,78,e9,5b,a5,63,11,c3,8b,74,4a,00,e3,..
"khjeh"=hex:1c,d7,0b,03,d5,1c,8f,fa,08,de,5f,11,8c,6b,d0,0b,fe,e9,24,fb,5a,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00

000001\0Jf40]
"khjeh"=hex:91,98,40,81,c7,01,a7,4a,6a,01,72,55,77,d1,83,35,89,cb,a3,98,4c,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00

000001\0Jf41]
"khjeh"=hex:69,18,bf,e8,d6,cb,73,30,96,ab,45,21,c5,1b,b4,b7,fc,0e,df,34,85,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:1e,e1,6b,79,01,79,86,81,ff,cc,c8,41,0f,e1,51,2e,d3,ba,a5,ee,9a,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\000000

01]
"a0"=hex:20,01,00,00,9d,be,84,14,7a,78,e9,5b,a5,63,11,c3,8b,74,4a,00,e3,..
"khjeh"=hex:1c,d7,0b,03,d5,1c,8f,fa,08,de,5f,11,8c,6b,d0,0b,fe,e9,24,fb,5a,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\000000

01\0Jf40]
"khjeh"=hex:91,98,40,81,c7,01,a7,4a,6a,01,72,55,77,d1,83,35,89,cb,a3,98,4c,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\000000

01\0Jf41]
"khjeh"=hex:69,18,bf,e8,d6,cb,73,30,96,ab,45,21,c5,1b,b4,b7,fc,0e,df,34,85,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000000
"TracesSuccessful"=dword:00000000
"LastTraceFailure"=dword:00000000

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 17


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\stand

ardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program

Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers

communs\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers

communs\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
"C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN

Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN

Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Fichiers communs\\AOL\\1195902532\\ee\\aolsoftware.exe"="C:\\Program

Files\\Fichiers communs\\AOL\\1195902532\\ee\\aolsoftware.exe:*:Enabled:AOL Shared Components"
"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"="C:\\Program

Files\\Java\\jre1.5.0_06\\bin\\javaw.exe:*:Disabled:Java(TM) 2 Platform Standard Edition binary"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network

Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program

Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program

Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program

Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program

Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"="C:\\Program

Files\\WiFiConnector\\NintendoWFCReg.exe:*:Enabled:Connecteur Wi-Fi USB Nintendo"
"C:\\Program Files\\Conference\\Conference.dll"="C:\\Program

Files\\Conference\\Conference.dll:*:Enabled:Audio/Video Conference"
"C:\\DOCUME~1\\mickael\\LOCALS~1\\Temp\\dllhost.exe"="C:\\DOCUME~1\\mickael\\LOCALS~1\\Temp\\dllho

st.exe:*:Enabled:Flash Player2"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:svchost"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domai

nprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers

communs\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers

communs\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN

Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN

Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network

Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 10 Dec 2006 211 A.SHR --- "C:\BOOT.BAK"
Tue 31 May 2005 54,384 A..H. --- "C:\Program Files\AOL 9.0\aolphx.exe"
Tue 31 May 2005 156,784 A..H. --- "C:\Program Files\AOL 9.0\aoltray.exe"
Tue 31 May 2005 31,344 A..H. --- "C:\Program Files\AOL 9.0\RBM.exe"
Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
Sat 16 Dec 2006 4,184 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygz.dll"
Wed 2 Jan 2008 72,704 ..SHR --- "C:\Program Files\eRightSoft\SUPER\Setup.exe"
Fri 27 Oct 2006 15,872 A.SHR --- "C:\Program Files\eRightSoft\SUPER\_Setup.dll"
Tue 4 Jun 2002 84,992 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
Tue 4 Jun 2002 44,032 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
Tue 10 Dec 2002 73,766 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
Tue 10 Dec 2002 65,575 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
Tue 4 Jun 2002 20,480 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
Tue 10 Dec 2002 102,437 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
Tue 10 Dec 2002 176,165 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
Tue 10 Dec 2002 208,935 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
Tue 10 Dec 2002 217,127 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
Sat 3 Nov 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
Tue 10 Apr 2001 225,280 ...HR --- "C:\Program

Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
Tue 10 Dec 2002 245,805 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
Tue 10 Dec 2002 45,093 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
Tue 10 Dec 2002 98,341 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
Tue 10 Dec 2002 94,247 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
Tue 10 Dec 2002 90,151 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
Tue 10 Dec 2002 102,439 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
Mon 18 Feb 2008 0 A..H. ---

"C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT4.tmp"

Finished!

Répondre à el-chico66

Re,

Désolé, j'avais perdu ton sujet ! N'hésite pas à faire un UP !
Reposte un HijackThis :)

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

c'est quoi un UP ??

Ok je repposte l'hijackThis...


Logfile of Trend Micro

HijackThis v2.0.2
Scan saved at 18:07:23, on

14/03/2008
Platform: Windows XP SP2

(WinNT 5.01.2600)
MSIE: Internet Explorer v7.00

(7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.ex

e
C:\WINDOWS\system32\winlogo

n.exe
C:\WINDOWS\system32\services.

exe
C:\WINDOWS\system32\lsass.ex

e
C:\WINDOWS\system32\Ati2evxx

.exe
C:\WINDOWS\system32\svchost.

exe
C:\WINDOWS\System32\svchost.

exe
C:\WINDOWS\system32\brsvc01a

.exe
C:\WINDOWS\system32\spoolsv.

exe
C:\WINDOWS\system32\brss01a.

exe
C:\Program Files\Avira\AntiVir

PersonalEdition

Classic\avguard.exe
C:\Program Files\Avira\AntiVir

PersonalEdition

Classic\sched.exe
C:\PROGRA~1\FICHIE~1\AOL\AC

S\AOLacsd.exe
C:\xampp\apache\bin\apache.ex

e
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.ex

e
C:\WINDOWS\eHome\ehSched.e

xe
C:\Program Files\Fichiers

communs\LightScribe\LSSrvc.ex

e
C:\xampp\mysql\bin\mysqld-nt.e

xe
C:\Program

Files\Nero\Nero8\Nero

BackItUp\NBService.exe
C:\Program

Files\CDBurnerXP\NMSAccessU.

exe
C:\WINDOWS\system32\svchost.

exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\Ati2evxx

.exe
C:\WINDOWS\Explorer.EXE
C:\xampp\apache\bin\apache.ex

e
C:\WINDOWS\system32\dllhost.e

xe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.ex

e
C:\Program Files\Fichiers

communs\AOL\1195902532\ee\A

OLSoftware.exe
C:\Program

Files\TOPRO\TPPOLL.EXE
C:\WINDOWS\OV530EM.exe
C:\Program

Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir

PersonalEdition

Classic\avgnt.exe
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program

Files\Nero\Nero8\Nero

BackItUp\NBKeyScan.exe
C:\WINDOWS\system32\ctfmon.e

xe
C:\Program Files\MSN

Messenger\msnmsgr.exe
C:\Program Files\AOL

9.0\aoltray.exe
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program

Files\WiFiConnector\NintendoW

FCReg.exe
C:\WINDOWS\System32\svchost.

exe
C:\WINDOWS\system32\wscntfy.

exe
C:\Program Files\MSN

Messenger\usnsvc.exe
C:\Program Files\AOL

Compagnon\companion.exe
C:\Program Files\Mozilla

Firefox\firefox.exe
C:\Program Files\Trend

Micro\HijackThis\HijackThis.exe

R1 -

HKCU\Software\Microsoft\Intern

et

Explorer\Main,Default_Page_UR

L =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iehome&locale=FR_

FR&c=64&bd=PAVILION&pf=des

ktop
R1 -

HKCU\Software\Microsoft\Intern

et

Explorer\Main,Default_Search_U

RL =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iesearch&locale=FR

_FR&c=64&bd=PAVILION&pf=de

sktop
R1 -

HKCU\Software\Microsoft\Intern

et Explorer\Main,Search Bar =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iesearch&locale=FR

_FR&c=64&bd=PAVILION&pf=de

sktop
R1 -

HKCU\Software\Microsoft\Intern

et Explorer\Main,Search Page =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iesearch&locale=FR

_FR&c=64&bd=PAVILION&pf=de

sktop
R0 -

HKCU\Software\Microsoft\Intern

et Explorer\Main,Start Page =

http://google.fr/
R1 -

HKLM\Software\Microsoft\Intern

et

Explorer\Main,Default_Page_UR

L = http://www.yahoo.com
R1 -

HKLM\Software\Microsoft\Intern

et

Explorer\Main,Default_Search_U

RL =

http://fr.rd.yahoo.com/customize

/ie/defaults/su/msgr8/*http://fr.se

arch.yahoo.com
R1 -

HKLM\Software\Microsoft\Intern

et Explorer\Main,Search Bar =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iesearch&locale=FR

_FR&c=64&bd=PAVILION&pf=de

sktop
R1 -

HKLM\Software\Microsoft\Intern

et Explorer\Main,Search Page =

http://fr.rd.yahoo.com/customize

/ie/defaults/sp/msgr8/*http://fr.se

arch.yahoo.com
R0 -

HKLM\Software\Microsoft\Intern

et Explorer\Main,Start Page =

http://www.yahoo.com
R0 -

HKLM\Software\Microsoft\Intern

et

Explorer\Search,SearchAssistan

t =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iesearch&locale=FR

_FR&c=64&bd=PAVILION&pf=de

sktop
R1 -

HKCU\Software\Microsoft\Intern

et Explorer\Main,Window Title =

Alice ADSL
R0 -

HKCU\Software\Microsoft\Intern

et

Explorer\Toolbar,LinksFolderNa

me = Liens
R3 - URLSearchHook: (no name)

-

{9CB65206-89C4-402c-BA80-02D

8C59F9B1D} - C:\Program

Files\AskTBar\SrchAstt\1.bin\A5

SRCHAS.DLL
O2 - BHO: Yahoo! Toolbar

Helper -

{02478D38-C3F9-4efb-9B51-7695

ECA05670} - C:\Program

Files\Yahoo!\Companion\Installs

\cpn\yt.dll
O2 - BHO: Aide pour le lien

d'Adobe PDF Reader -

{06849E9F-C8D7-4D59-B87D-784

B7D6BE0B3} - C:\Program

Files\Fichiers

communs\Adobe\Acrobat\Active

X\AcroIEHelper.dll
O2 - BHO: ShoppingReport -

{100EB1FD-D03E-47FD-81F3-EE9

1287F9465} - C:\Program

Files\ShoppingReport\Bin\2.5.0\

ShoppingReport.dll
O2 - BHO: RealPlayer Download

and Record Plugin for Internet

Explorer -

{3049C3E9-B461-4BC5-8870-4C0

9146192CA} - C:\Program

Files\Real\RealPlayer\rpbrowserr

ecordplugin.dll
O2 - BHO: EoBho Class -

{64F56FC1-1272-44CD-BA6E-397

23696E350} - C:\Program

Files\EoRezo\EoAdv\EoRezoBH

O.dll (file missing)
O2 - BHO: SSVHelper Class -

{761497BB-D6F0-462C-B6EB-D4

DAF1D92D43} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) -

{7E853D72-626A-48EC-A868-BA8

D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in

Helper -

{9030D464-4C02-4ABF-8ECC-516

4760863C6} - C:\Program

Files\Fichiers

communs\Microsoft

Shared\Windows

Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant

BHO -

{9CB65201-89C4-402c-BA80-02D

8C59F9B1D} - C:\Program

Files\AskTBar\SrchAstt\1.bin\A5

SRCHAS.DLL
O2 - BHO: Ask Toolbar BHO -

{FE063DB1-4EC0-403e-8DD8-394

C54984B2C} - C:\Program

Files\AskTBar\bar\1.bin\ASKTBA

R.DLL
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-009

0271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs

\cpn\yt.dll
O3 - Toolbar: Ask Toolbar -

{FE063DB9-4EC0-403e-8DD8-394

C54984B2C} - C:\Program

Files\AskTBar\bar\1.bin\ASKTBA

R.DLL
O4 - HKLM\..\Run: [ehTray]

C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2]

rundll32.exe

ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL]

RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady

Power Message APP]

ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard]

C:\WINDOWS\SMINST\RECGUA

RD.EXE
O4 - HKLM\..\Run:

[HostManager] C:\Program

Files\Fichiers

communs\AOL\1195902532\ee\A

OLSoftware.exe
O4 - HKLM\..\Run: [TPPOLL]

C:\Program

Files\TOPRO\TPPOLL.EXE
O4 - HKLM\..\Run: [Ovt Wia]

C:\WINDOWS\OV530EM.exe
O4 - HKLM\..\Run: [TkBellExe]

"C:\Program Files\Fichiers

communs\Real\Update_OB\reals

ched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime

Task] "C:\Program

Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [Defy Inside

Proc Heart] C:\Documents and

Settings\All Users\Application

Data\burn download defy

inside\Audio multi.exe
O4 - HKLM\..\Run: [avgnt]

"C:\Program Files\Avira\AntiVir

PersonalEdition

Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Itch ford four

knob] C:\Documents and

Settings\All Users\Application

Data\third lies itch ford\Ace

Media.exe
O4 - HKLM\..\Run:

[NeroFilterCheck] C:\Program

Files\Fichiers

communs\Nero\Lib\NeroCheck.e

xe
O4 - HKLM\..\Run: [NBKeyScan]

"C:\Program

Files\Nero\Nero8\Nero

BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe

Reader Speed Launcher]

"C:\Program Files\Adobe\Reader

8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.e

xe
O4 - HKCU\..\Run: [msnmsgr]

"C:\Program Files\MSN

Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [help amok]

C:\DOCUME~1\HP_ADM~1\APPL

IC~1\ONLINE~1\4styledash.exe
O4 - .DEFAULT User Startup:

Pin.lnk =

C:\hp\bin\CLOAKER.EXE (User

'Default user')
O4 - .DEFAULT User Startup:

PinMcLnk.lnk =

C:\hp\bin\cloaker.exe (User

'Default user')
O4 - Global Startup: AOL 9.0

Icône AOL.lnk = C:\Program

Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL

Compagnon.lnk = C:\Program

Files\AOL

Compagnon\companion.exe
O4 - Global Startup: Lancer

l'utilitaire d'enregistrement.lnk =

C:\Program

Files\WiFiConnector\NintendoW

FCReg.exe
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00

401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem:

Console Java (Sun) -

{08B0E5C0-4FCB-11CF-AAA5-00

401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button:

ShopperReports - Compare

product prices -

{C5428486-50A0-4a02-9D20-520B

59A9F9B2} - C:\Program

Files\ShoppingReport\Bin\2.5.0\

ShoppingReport.dll
O9 - Extra button:

ShopperReports - Compare

travel rates -

{C5428486-50A0-4a02-9D20-520B

59A9F9B3} - C:\Program

Files\ShoppingReport\Bin\2.5.0\

ShoppingReport.dll
O9 - Extra button: Aide à la

connexion -

{E2D4D26B-0180-43a4-B05F-462

D6D54C789} -

C:\WINDOWS\PCHEALTH\HELP

CTR\Vendors\CN=Hewlett-Packa

rd,L=Cupertino,S=Ca,C=US\IEBu

tton\support.htm
O9 - Extra 'Tools' menuitem:

Aide à la connexion -

{E2D4D26B-0180-43a4-B05F-462

D6D54C789} -

C:\WINDOWS\PCHEALTH\HELP

CTR\Vendors\CN=Hewlett-Packa

rd,L=Cupertino,S=Ca,C=US\IEBu

tton\support.htm
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba3

8496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:

@xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba3

8496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C

04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem:

Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C

04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF:

{20A60F0D-9AFA-4515-A0FD-83B

D84642501} (Checkers Class) -

http://messenger.zone.msn.com/

binary/msgrchkr.cab56986.cab
O16 - DPF:

{30528230-99f7-4bb4-88d8-fa1d4f

56a2ab} (Installation Support) -

C:\Program

Files\Yahoo!\Common\Yinsthelp

er.dll
O16 - DPF:

{5C051655-FCD5-4969-9182-770E

A5AA5565} (Solitaire Showdown

Class) -

http://messenger.zone.msn.com/

binary/SolitaireShowdown.cab5

6986.cab
O16 - DPF:

{5D6F45B3-9043-443D-A792-1154

47494D24} (UnoCtrl Class) -

http://messenger.zone.msn.com/

FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF:

{7FC1B346-83E6-4774-8D20-1A6

B09B0E737} (Windows Live

Photo Upload Control) -

http://xel-chicox.spaces.live.com

/PhotoUpload/MsnPUpld.cab
O16 - DPF:

{8F48147B-78D9-40F9-ACC0-BD

DE59B246F4} (AccountHelper

Class) -

http://abonnement.aliceadsl.fr/c

onfigurateur/AccountHelper.cab
O16 - DPF:

{B8BE5E93-A60C-4D26-A2DC-22

0313175592} (MSN Games -

Installer) -

http://messenger.zone.msn.com/

binary/ZIntro.cab56649.cab
O16 - DPF:

{BD8667B7-38D8-4C77-B580-18C

3E146372C} (Creative Toolbox

Plug-in) -

http://bmm.imgag.com/imgag/cp

/install/crusher-fr.cab
O16 - DPF:

{BFF1950D-B1B4-4AE8-B842-B2

CCF06D9A1B} (Zylom Games

Player) -

http://game07.zylom.com/activex

/zylomgamesplayer.cab
O16 - DPF:

{C3F79A2B-B9B4-4A66-B012-3E

E46475B072}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/

binary/MessengerStatsPAClient.

cab56907.cab
O16 - DPF:

{D0C0F75C-683A-4390-A791-1AC

FD5599AB8} (Oberon Flash

Game Host) -

http://jeuxenligne.orange.fr/Gam

eshell/GameHost/1.0/OberonGa

meHost.cab
O16 - DPF:

{DF780F87-FF2B-4DF8-92D0-73D

B16A1543A} (PopCapLoader

Object) -

http://jeuxenligne.orange.fr/Gam

eShell/online/fr/hammer_heads/

popcaploader_v6.cab
O23 - Service: Adobe LM Service

- Adobe Systems - C:\Program

Files\Fichiers communs\Adobe

Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir

PersonalEdition Classic

Scheduler (AntiVirScheduler) -

Avira GmbH - C:\Program

Files\Avira\AntiVir

PersonalEdition

Classic\sched.exe
O23 - Service: AntiVir

PersonalEdition Classic Guard

(AntiVirService) - Avira GmbH -

C:\Program Files\Avira\AntiVir

PersonalEdition

Classic\avguard.exe
O23 - Service: AOL Connectivity

Service (AOL ACS) - AOL LLC -

C:\PROGRA~1\FICHIE~1\AOL\AC

S\AOLacsd.exe
O23 - Service: Apache2.2 -

Apache Software Foundation -

C:\xampp\apache\bin\apache.ex

e
O23 - Service: Ati HotKey Poller -

ATI Technologies Inc. -

C:\WINDOWS\system32\Ati2evxx

.exe
O23 - Service: BrSplService

(Brother XP spl Service) -

brother Industries Ltd -

C:\WINDOWS\system32\brsvc01a

.exe
O23 - Service: FileZilla Server

FTP server (FileZilla Server) -

FileZilla Project -

c:\xampp\FileZillaFTP\FileZillaSe

rver.exe
O23 - Service: InstallDriver Table

Manager (IDriverT) - Macrovision

Corporation - C:\Program

Files\Fichiers

communs\InstallShield\Driver\10

50\Intel 32\IDriverT.exe
O23 - Service:

LightScribeService Direct Disc

Labeling Service

(LightScribeService) -

Hewlett-Packard Company -

C:\Program Files\Fichiers

communs\LightScribe\LSSrvc.ex

e
O23 - Service: mysql - Unknown

owner -

C:\xampp\mysql\bin\mysqld-nt.e

xe
O23 - Service: Nero BackItUp

Scheduler 3 - Nero AG -

C:\Program

Files\Nero\Nero8\Nero

BackItUp\NBService.exe
O23 - Service: NMSAccessU -

Unknown owner - C:\Program

Files\CDBurnerXP\NMSAccessU.

exe
O23 - Service: ServiceLayer -

Nokia. - C:\Program Files\PC

Connectivity

Solution\ServiceLayer.exe
O23 - Service: WAN Miniport

(ATW) Service

(WANMiniportService) - America

Online, Inc. -

C:\WINDOWS\wanmpsvc.exe

--
End of file - 12518 bytes

Répondre à el-chico66

Reposte le rapport, c'est illisible.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:18:47, on 16/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Fichiers communs\AOL\1195902532\ee\AOLSoftware.exe
C:\Program Files\TOPRO\TPPOLL.EXE
C:\WINDOWS\OV530EM.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ViiincEnt\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/french
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/i [...] .yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shell.windows.com/fileassoc [...] 0c&Ext=tdc
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1195902532\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [TPPOLL] C:\Program Files\TOPRO\TPPOLL.EXE
O4 - HKLM\..\Run: [Ovt Wia] C:\WINDOWS\OV530EM.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Defy Inside Proc Heart] C:\Documents and Settings\All Users\Application Data\burn download defy inside\Audio multi.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Itch ford four knob] C:\Documents and Settings\All Users\Application Data\third lies itch ford\Ace Media.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [help amok] C:\Documents and Settings\ViiincEnt\Application Data\online eq\4styledash.exe
O4 - HKCU\..\Run: [EasyFlirt Messenger] C:\Program Files\EasyFlirt Messenger\EasyFlirt Messenger.exe /M
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Compagnon.lnk = C:\Program Files\AOL Compagnon\companion.exe
O4 - Global Startup: Lancer l'utilitaire d'enregistrement.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://xel-chicox.spaces.live.com/ [...] nPUpld.cab
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/con [...] Helper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Games [...] meHost.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://jeuxenligne.orange.fr/GameS [...] der_v6.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - c:\xampp\FileZillaFTP\FileZillaServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 14584 bytes

Répondre à el-chico66

Re,

 

Télécharge Lop S&D.exe ( d' Eric 71 & Angeldark ) sur ton bureau. ~>Tuto<~

 
  • Double-clique dessus pour lancer l'installation
  • Puis double-clique sur le raccourci Lop S&D présent sur ton bureau (Si tu es sous Vista, clique droit -> exécuter en tant qu'admin)
  • Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
  • Patiente jusqu'à la fin du scan
  • Poste le rapport généré ( C:\lopR.txt )


(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)

 

*******

 

Télécharge BTFix (de Bibi26)
Dézippe le sur ton Bureau.
Ouvre le dossier BTFix.
Double clique sur BTFix.exe.
Clique sur Rechercher.
Un rapport va apparaître, poste le ici.


Message édité par XmichouX le 16-03-2008 à 22:02:04
------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX


-----------------------[ Lop S&D 4.0.7 XP/Vista ]----------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : ViiincEnt ] [ "C:\Lop SD" ]
[ 16/03/2008 | 23:18:41,28 ] [ PC : NOM-FB9B15D2723 ]
[ MAJ : 13-03-2008 | 20:45 ]

-------------[ Listing des dossiers dans Application Data ]------------

[14/10/2007|12:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[14/10/2007|12:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[10/10/2005|14:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[15/11/2005|03:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[04/09/2006|23:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[04/09/2006|23:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real

[16/03/2008|19:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[16/03/2008|19:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[07/02/2008|22:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\addr_file.html
[18/02/2008|02:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[07/02/2008|20:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[24/11/2007|12:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[07/02/2008|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[01/02/2007|20:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Brother
[16/02/2008|15:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\burn download defy inside
[04/09/2006|23:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[10/10/2005|14:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[23/01/2008|13:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[04/09/2006|23:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
[04/09/2006|23:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[16/03/2008|19:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[16/03/2008|19:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[04/09/2006|23:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[24/11/2007|18:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[25/12/2007|19:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[16/02/2008|16:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[10/01/2008|16:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[26/01/2008|16:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
[03/02/2007|17:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[04/09/2006|22:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[01/02/2007|20:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[04/09/2006|23:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[14/10/2007|12:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[16/02/2008|15:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\third lies itch ford
[03/02/2007|17:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[21/12/2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[17/01/2008|02:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[17/01/2008|02:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[10/01/2008|16:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[14/10/2007|12:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[14/10/2007|12:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[10/10/2005|14:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[15/11/2005|03:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[04/09/2006|23:50] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[04/09/2006|23:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real


[21/02/2008|20:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\.
[21/02/2008|20:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\..
[07/02/2008|21:09] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Adobe
[24/11/2007|14:27] C:\DOCUME~1\HP_ADM~1\APPLIC~1\AdobeUM
[03/02/2007|19:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\AOL
[21/02/2008|20:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\cs
[19/12/2006|18:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\CyberLink
[10/10/2005|14:24] C:\DOCUME~1\HP_ADM~1\APPLIC~1\desktop.ini
[30/11/2007|22:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\DivX
[06/01/2008|20:41] C:\DOCUME~1\HP_ADM~1\APPLIC~1\EoRezo
[28/11/2007|18:20] C:\DOCUME~1\HP_ADM~1\APPLIC~1\G-Force Prefs (WindowsMediaPlayer).txt
[07/01/2008|17:14] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Google
[20/03/2007|19:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Help
[07/01/2007|18:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HP
[11/12/2006|21:23] C:\DOCUME~1\HP_ADM~1\APPLIC~1\HPQ
[10/01/2008|16:51] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Identities
[01/02/2007|20:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\InterTrust
[10/12/2006|21:31] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Leadertech
[23/01/2008|14:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\LimeWire
[01/02/2007|19:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Macromedia
[06/01/2008|20:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Microsoft
[20/12/2007|18:06] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Mozilla
[23/01/2008|13:08] C:\DOCUME~1\HP_ADM~1\APPLIC~1\MSNInstaller
[19/02/2008|10:57] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Nero
[03/02/2008|15:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Notepad++
[03/03/2008|21:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\online eq
[03/02/2008|14:29] C:\DOCUME~1\HP_ADM~1\APPLIC~1\OpenOffice.org2
[10/01/2008|15:07] C:\DOCUME~1\HP_ADM~1\APPLIC~1\PC Suite
[10/01/2008|16:51] C:\DOCUME~1\HP_ADM~1\APPLIC~1\PlayFirst
[25/01/2008|23:06] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Real
[28/02/2007|22:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ScanSoft
[25/12/2007|03:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\SecuROM
[15/03/2008|20:16] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ShoppingReport
[10/12/2006|21:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sonic
[21/11/2007|20:04] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Sun
[20/12/2007|18:07] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Talkback
[10/12/2006|21:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Template
[13/12/2007|19:10] C:\DOCUME~1\HP_ADM~1\APPLIC~1\vlc
[01/11/2007|17:40] C:\DOCUME~1\HP_ADM~1\APPLIC~1\WinRAR
[26/10/2007|16:25] C:\DOCUME~1\HP_ADM~1\APPLIC~1\wklnhst.dat
[07/12/2007|12:53] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Yahoo!
[03/02/2007|17:03] C:\DOCUME~1\HP_ADM~1\APPLIC~1\You've Got Pictures Screensaver
[10/01/2008|16:51] C:\DOCUME~1\HP_ADM~1\APPLIC~1\Zylom

[04/09/2006|22:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[04/09/2006|22:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[20/01/2008|16:15] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[22/02/2008|14:41] C:\DOCUME~1\mickael\APPLIC~1\.
[22/02/2008|14:41] C:\DOCUME~1\mickael\APPLIC~1\..
[23/01/2008|00:03] C:\DOCUME~1\mickael\APPLIC~1\Adobe
[10/10/2005|14:24] C:\DOCUME~1\mickael\APPLIC~1\desktop.ini
[15/11/2005|03:22] C:\DOCUME~1\mickael\APPLIC~1\Identities
[24/01/2008|23:49] C:\DOCUME~1\mickael\APPLIC~1\LimeWire
[23/01/2008|00:03] C:\DOCUME~1\mickael\APPLIC~1\Macromedia
[22/01/2008|23:53] C:\DOCUME~1\mickael\APPLIC~1\Microsoft
[21/02/2008|20:58] C:\DOCUME~1\mickael\APPLIC~1\Nero
[22/01/2008|23:58] C:\DOCUME~1\mickael\APPLIC~1\online eq
[04/09/2006|23:08] C:\DOCUME~1\mickael\APPLIC~1\Real
[22/02/2008|14:41] C:\DOCUME~1\mickael\APPLIC~1\ShoppingReport
[23/01/2008|17:22] C:\DOCUME~1\mickael\APPLIC~1\vlc

[04/09/2006|22:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[04/09/2006|22:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[04/09/2006|22:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[23/02/2008|15:29] C:\DOCUME~1\VIIINC~1\APPLIC~1\.
[23/02/2008|15:29] C:\DOCUME~1\VIIINC~1\APPLIC~1\..
[09/02/2008|20:15] C:\DOCUME~1\VIIINC~1\APPLIC~1\Adobe
[31/10/2007|18:52] C:\DOCUME~1\VIIINC~1\APPLIC~1\AOL
[06/12/2007|22:12] C:\DOCUME~1\VIIINC~1\APPLIC~1\Azureus
[09/11/2007|17:52] C:\DOCUME~1\VIIINC~1\APPLIC~1\CyberLink
[16/02/2008|16:00] C:\DOCUME~1\VIIINC~1\APPLIC~1\DAEMON Tools
[10/10/2005|14:24] C:\DOCUME~1\VIIINC~1\APPLIC~1\desktop.ini
[17/11/2007|14:14] C:\DOCUME~1\VIIINC~1\APPLIC~1\DivX
[08/02/2008|20:24] C:\DOCUME~1\VIIINC~1\APPLIC~1\Ecran de veille
[17/01/2008|02:04] C:\DOCUME~1\VIIINC~1\APPLIC~1\Google
[02/12/2007|16:58] C:\DOCUME~1\VIIINC~1\APPLIC~1\Help
[02/12/2007|16:12] C:\DOCUME~1\VIIINC~1\APPLIC~1\HPQ
[15/11/2005|03:22] C:\DOCUME~1\VIIINC~1\APPLIC~1\Identities
[09/02/2008|17:22] C:\DOCUME~1\VIIINC~1\APPLIC~1\Leadertech
[05/01/2008|17:51] C:\DOCUME~1\VIIINC~1\APPLIC~1\LimeWire
[24/11/2007|18:44] C:\DOCUME~1\VIIINC~1\APPLIC~1\Macromedia
[25/02/2008|18:24] C:\DOCUME~1\VIIINC~1\APPLIC~1\Microsoft
[07/02/2008|22:41] C:\DOCUME~1\VIIINC~1\APPLIC~1\Mozilla
[16/02/2008|17:02] C:\DOCUME~1\VIIINC~1\APPLIC~1\Nero
[29/01/2008|21:18] C:\DOCUME~1\VIIINC~1\APPLIC~1\Notepad++
[23/02/2008|15:29] C:\DOCUME~1\VIIINC~1\APPLIC~1\Nvu
[16/02/2008|15:06] C:\DOCUME~1\VIIINC~1\APPLIC~1\online eq
[19/02/2008|16:29] C:\DOCUME~1\VIIINC~1\APPLIC~1\OpenOffice.org2
[09/11/2007|17:11] C:\DOCUME~1\VIIINC~1\APPLIC~1\Real
[07/03/2008|12:27] C:\DOCUME~1\VIIINC~1\APPLIC~1\ShoppingReport
[09/02/2008|17:22] C:\DOCUME~1\VIIINC~1\APPLIC~1\Sonic
[09/02/2008|19:10] C:\DOCUME~1\VIIINC~1\APPLIC~1\Sun
[24/11/2007|16:43] C:\DOCUME~1\VIIINC~1\APPLIC~1\SYSTRAN
[02/12/2007|16:28] C:\DOCUME~1\VIIINC~1\APPLIC~1\Talkback
[09/11/2007|17:37] C:\DOCUME~1\VIIINC~1\APPLIC~1\Template
[07/02/2008|22:41] C:\DOCUME~1\VIIINC~1\APPLIC~1\Thunderbird
[16/03/2008|22:35] C:\DOCUME~1\VIIINC~1\APPLIC~1\uTorrent
[22/12/2007|13:29] C:\DOCUME~1\VIIINC~1\APPLIC~1\vlc
[17/11/2007|14:09] C:\DOCUME~1\VIIINC~1\APPLIC~1\WinRAR
[24/11/2007|15:31] C:\DOCUME~1\VIIINC~1\APPLIC~1\wklnhst.dat
[07/12/2007|18:26] C:\DOCUME~1\VIIINC~1\APPLIC~1\Yahoo!

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[21/02/2008 14:14][--a------] C:\WINDOWS\tasks\Connexion facile … Internet.job
[16/03/2008 23:00][--ah-----] C:\WINDOWS\tasks\A4DA671F918A17BB.job
[16/03/2008 23:00][--ah-----] C:\WINDOWS\tasks\B73401E0919BAC10.job
[15/03/2008 20:23][--ah-----] C:\WINDOWS\tasks\SA.DAT
[10/08/2004 12:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[16/03/2008|21:05] C:\Program Files\.
[16/03/2008|21:05] C:\Program Files\..
[16/03/2008|21:06] C:\Program Files\Activision
[18/02/2008|02:01] C:\Program Files\Adobe
[24/11/2007|17:00] C:\Program Files\Adverts
[16/11/2007|13:03] C:\Program Files\Alice
[07/02/2008|21:39] C:\Program Files\Alwil Software
[08/02/2008|23:46] C:\Program Files\Anthemis
[24/11/2007|12:09] C:\Program Files\AOL
[24/11/2007|17:31] C:\Program Files\AOL 9.0
[24/11/2007|17:31] C:\Program Files\AOL Compagnon
[13/02/2008|12:37] C:\Program Files\AskTBar
[04/09/2006|22:59] C:\Program Files\ATI Technologies
[07/02/2008|22:13] C:\Program Files\Avira
[02/01/2008|19:04] C:\Program Files\AviSynth 2.5
[06/12/2007|22:12] C:\Program Files\Azureus
[09/03/2008|12:44] C:\Program Files\CDBurnerXP
[22/12/2007|13:13] C:\Program Files\Circle Developement
[12/11/2005|01:09] C:\Program Files\ComPlus Applications
[03/02/2008|16:26] C:\Program Files\Conference
[16/02/2008|16:05] C:\Program Files\DAEMON Tools Lite
[03/02/2008|16:27] C:\Program Files\DBZ Online V6
[10/01/2008|15:07] C:\Program Files\DIFX
[03/03/2008|15:24] C:\Program Files\DivX
[16/03/2008|20:32] C:\Program Files\DVD Decrypter
[04/09/2006|23:30] C:\Program Files\EasyBits
[24/01/2008|18:24] C:\Program Files\EasyBits For Kids
[14/02/2008|12:58] C:\Program Files\Empire Interactive
[16/03/2008|22:22] C:\Program Files\eMule
[06/01/2008|20:41] C:\Program Files\EoRezo
[02/01/2008|19:03] C:\Program Files\eRightSoft
[13/03/2008|13:13] C:\Program Files\Everest Poker
[26/09/2007|13:11] C:\Program Files\Fast Food Empire
[16/02/2008|16:57] C:\Program Files\Fichiers communs
[06/01/2008|20:38] C:\Program Files\FreebieSMS
[04/09/2006|22:37] C:\Program Files\FrenchOtto
[04/09/2006|22:37] C:\Program Files\GemMasterFrench
[23/01/2008|13:13] C:\Program Files\Google
[04/09/2006|23:46] C:\Program Files\Hewlett-Packard
[04/09/2006|23:11] C:\Program Files\HP
[04/09/2006|23:08] C:\Program Files\HP DigitalMedia Archive
[16/03/2008|19:01] C:\Program Files\IncrediMail
[17/02/2008|04:22] C:\Program Files\InstallShield Installation Information
[08/12/2007|17:18] C:\Program Files\Interapple
[13/02/2008|03:01] C:\Program Files\Internet Explorer
[04/09/2006|22:44] C:\Program Files\Java
[10/05/2007|11:06] C:\Program Files\JoWood
[24/12/2007|17:35] C:\Program Files\Kerio
[04/01/2008|18:05] C:\Program Files\Lavalys
[03/02/2008|16:28] C:\Program Files\LimeWire
[03/02/2008|16:43] C:\Program Files\Lopxp
[19/01/2008|18:02] C:\Program Files\Ludiclub
[23/01/2008|13:04] C:\Program Files\Ma Pension d'Animaux
[03/02/2008|03:01] C:\Program Files\Ma‹do Production
[02/02/2007|00:11] C:\Program Files\Maxis
[04/09/2006|22:48] C:\Program Files\Messenger
[22/12/2007|13:13] C:\Program Files\Messenger Plus! Live
[15/11/2005|03:24] C:\Program Files\microsoft frontpage
[04/09/2006|23:13] C:\Program Files\Microsoft Office
[04/09/2006|23:13] C:\Program Files\Microsoft Works
[15/11/2005|03:24] C:\Program Files\Movie Maker
[16/03/2008|23:15] C:\Program Files\Mozilla Firefox
[16/03/2008|18:58] C:\Program Files\Mozilla Thunderbird
[23/01/2008|13:08] C:\Program Files\MSN
[15/11/2005|03:25] C:\Program Files\MSN Gaming Zone
[11/12/2007|16:57] C:\Program Files\MSN Messenger
[22/11/2007|03:01] C:\Program Files\MSXML 4.0
[04/09/2006|23:15] C:\Program Files\muvee Technologies
[16/02/2008|16:57] C:\Program Files\Nero
[15/11/2005|03:25] C:\Program Files\NetMeeting
[23/02/2008|15:19] C:\Program Files\nLite
[29/01/2008|20:11] C:\Program Files\Notepad++
[16/03/2008|20:28] C:\Program Files\Nvu
[16/02/2008|15:05] C:\Program Files\online eq
[15/11/2005|03:25] C:\Program Files\Online Services
[01/11/2007|17:35] C:\Program Files\OpenOffice.org 2.2
[22/11/2007|03:07] C:\Program Files\Outlook Express
[10/01/2008|15:01] C:\Program Files\PC Connectivity Solution
[04/01/2008|16:03] C:\Program Files\PhotoFiltre Studio
[08/02/2008|21:23] C:\Program Files\PSCS2Updater
[03/02/2007|17:03] C:\Program Files\QuickTime
[04/09/2006|23:08] C:\Program Files\Real
[01/02/2007|20:36] C:\Program Files\ScanSoft
[04/09/2006|23:32] C:\Program Files\Services en ligne
[19/02/2008|01:33] C:\Program Files\SFRlite
[16/02/2008|16:06] C:\Program Files\ShoppingReport
[22/02/2008|20:24] C:\Program Files\SM
[04/09/2006|23:10] C:\Program Files\Sonic
[16/11/2007|13:03] C:\Program Files\TechCity Solutions
[25/11/2007|17:27] C:\Program Files\Topro
[20/12/2007|19:46] C:\Program Files\Trend Micro
[12/11/2005|01:09] C:\Program Files\Uninstall Information
[15/02/2008|19:15] C:\Program Files\uTorrent
[13/12/2007|19:10] C:\Program Files\VideoLAN
[03/02/2007|17:03] C:\Program Files\Viewpoint
[20/11/2007|11:47] C:\Program Files\Windows Live
[12/03/2008|17:48] C:\Program Files\Windows Live Safety Center
[23/11/2007|09:14] C:\Program Files\Windows Media Player
[15/11/2005|03:25] C:\Program Files\Windows NT
[15/11/2005|03:25] C:\Program Files\Windows Plus
[12/11/2005|01:09] C:\Program Files\WindowsUpdate
[01/11/2007|17:40] C:\Program Files\WinRAR
[15/11/2005|03:26] C:\Program Files\xerox
[02/01/2008|17:32] C:\Program Files\Xilisoft
[23/01/2008|23:00] C:\Program Files\Yahoo!
[03/02/2008|16:27] C:\Program Files\Zylom Games

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[16/02/2008|16:57] C:\Program Files\Fichiers communs\.
[16/02/2008|16:57] C:\Program Files\Fichiers communs\..
[18/02/2008|02:01] C:\Program Files\Fichiers communs\Adobe
[08/02/2008|20:18] C:\Program Files\Fichiers communs\Adobe Systems Shared
[24/11/2007|12:15] C:\Program Files\Fichiers communs\AOL
[03/02/2007|17:03] C:\Program Files\Fichiers communs\aolshare
[04/09/2006|23:04] C:\Program Files\Fichiers communs\HP
[02/02/2007|00:04] C:\Program Files\Fichiers communs\InstallShield
[04/09/2006|22:43] C:\Program Files\Fichiers communs\Java
[16/02/2008|17:26] C:\Program Files\Fichiers communs\LightScribe
[04/09/2006|23:11] C:\Program Files\Fichiers communs\LS Getting Started
[03/02/2008|03:01] C:\Program Files\Fichiers communs\Microsoft Shared
[15/11/2005|03:24] C:\Program Files\Fichiers communs\MSSoap
[04/09/2006|23:14] C:\Program Files\Fichiers communs\muvee Technologies
[16/02/2008|17:00] C:\Program Files\Fichiers communs\Nero
[03/02/2007|17:03] C:\Program Files\Fichiers communs\Nullsoft
[15/11/2005|03:24] C:\Program Files\Fichiers communs\ODBC
[24/01/2008|23:02] C:\Program Files\Fichiers communs\Real
[01/02/2007|20:36] C:\Program Files\Fichiers communs\ScanSoft Shared
[15/11/2005|03:24] C:\Program Files\Fichiers communs\Services
[04/09/2006|23:09] C:\Program Files\Fichiers communs\Sonic Shared
[15/11/2005|03:24] C:\Program Files\Fichiers communs\SpeechEngines
[04/09/2006|23:09] C:\Program Files\Fichiers communs\SureThing Shared
[14/10/2007|12:29] C:\Program Files\Fichiers communs\Symantec Shared
[22/11/2007|03:07] C:\Program Files\Fichiers communs\System
[04/09/2006|23:10] C:\Program Files\Fichiers communs\TiVo Shared
[24/01/2008|23:02] C:\Program Files\Fichiers communs\xing shared

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ALLUSE~1\APPLIC~1\third lies itch ford
C:\DOCUME~1\ALLUSE~1\APPLIC~1\third lies itch ford\Ace Media.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\third lies itch ford\locks soft.exe
C:\Program Files\Adverts
C:\Program Files\Circle Developement
C:\Program Files\Circle Developement\Uninstall.exe
C:\WINDOWS\Tasks\A4DA671F918A17BB.job
C:\WINDOWS\Tasks\B73401E0919BAC10.job

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Itch ford four knob"="C:\\Documents and Settings\\All Users\\Application Data\\third lies itch ford\\Ace Media.exe"

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 23:19:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
scan completed successfully
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:67791][Doss:85] C:\DOCUME~1\VIIINC~1\LOCALS~1\Temp
/!\ [Fich:88][Doss:0] C:\DOCUME~1\VIIINC~1\Cookies
/!\ [Fich:16686][Doss:49] C:\DOCUME~1\VIIINC~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 23:23:04,79 ]----------------------





et



BTFix 1.086 (par bibi26) - 16/03/2008 23:25:23 - Analyse
Lancé depuis C:\Documents and Settings\ViiincEnt\Bureau\BTFix\BTFix.exe

---> Fichiers/Dossiers trouvés

- C:\Program Files\ShoppingReport\
- C:\Program Files\AskTBar\
- C:\Documents and Settings\ViiincEnt\Application Data\ShoppingReport\

---> Analyse terminée

Répondre à el-chico66

Re,

Désinstalle via ajout/suppr de programmes :
Eoreozo.

Relance Lop S&D

  • Choisis cette fois ci l'Option 2 ( Suppression )
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré ( C:\lopR.txt )


(Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)

*********

Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\
Relance Btfix, clique sur nettoyer, poste le rapport généré.

******

Télécharger OTMoveIt2. ( de OldTimer)

  • Enregistrece fichier sur le Bureau.
  • Fais un double clic sur OTMoveIt2.exe pour lancer l'exécution de l'outil. (Note: Si tu utilises Vista, fais un clic droit sur le fichier puis choisissez Exécuter en tant qu'administrateur).
  • Copie les lignes de la zone "Code" ci-dessous en les sélectionnant TOUTES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier):

C:\DOCUME~1\HP_ADM~1\APPLIC~1\EoRezo
C:\DOCUME~1\ALLUSE~1\APPLIC~1\burn download defy inside
C:\Program Files\EoRezo


  • Retourne dans la fenêtre de OTMoveIt2, fais un clic droit dans la zone "Paste Standard List of Files/Folders to Move" (sous la barre bleu clair) puis choisis Coller.
  • Clique sur le bouton rouge Moveit!.
  • Copie tout ce qui se trouve dans la zone Results (sous la barre verte) en sélectionnant TOUTES LES LIGNES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier), et coller ces résulats en réponse sur le forum.
  • Ferme OTMoveIt2


Note: Si un fichier ou un dossier ne peut pas être déplacé immédiatement, un redémarrage sera peut-être nécessaire afin de terminer le processus de déplacement. Si le redémarrage de la machine t'est demandé, choisis Oui/Yes. Dans ce cas, après le redémarrage, ouvre le Bloc-notes (Démarrer->Tous les programmes->Accessoires->Bloc-notes), clique sur Fichier->Ouvrir, dans la zone "Nom du fichier" taper *.log et appuie sur la touche Entrée, navigue jusqu'au dossier C:\_OTMoveIt\MovedFiles, puis ouvre le fichier .log le plus récent; ensuite fais un copier/coller du contenu de ce document en réponse sur le forum.

Si tu obtiens un message comme quoi le rapport ne peut pas être créé, copie/colle ce qui apparaît dans la colonne droite de l’outil.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX
Tom's Guide > Forum > Sécurité - Virus > Mon pc ram !!! il ne veu plus rien faire
Aller à :

Il y a 613 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens