Tom's Guide > Forum > Sécurité - Virus > CiD sous Vista
Mot :    Pseudo :           
 

Salut,
Depuis 2 mois, je recois des Pubs nomées CiD lorsque j'ouvre une page internet. j'ai deja verifié et ce n'est pas à cause de MSN Live +. je ne sais vraiment plus quoi faire...... :cry:
quelqu'un peu m'aider à le supprimer svp! :??:


Message édité par Dias_ le 08-07-2008 à 18:58:30
------------------------------ Merci
Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Bonjour,

Télécharge Lop S&D.exe (Eric_71) sur ton Bureau.

  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique maintenant sur le raccourci de LopS&D.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré (C:\lopR.txt*)


(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
* le nom de la partition peut changer

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Merci, j’ai suivi ton conseil on ma demander « d’exécuter en tant qu’administrateur » et apres un redémarrage de mon ordinateur et apres la recherche on m’affiche ce qui suit :


-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------

[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 08/07/2008 | 20:48:00,49 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]

-------------[ Listing des dossiers dans Roaming ]------------

[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE

[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter

[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec

[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000

[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop

[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth

[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI

[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs


[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}

[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV


[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes

[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004



[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR

[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[08/07/2008|15:14] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials


[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles

[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash

[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore


[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache

[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console


[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion

[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer

----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------

[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[08/07/2008 20:47][--ah-----] C:\Windows\tasks\SA.DAT
[08/07/2008 20:46][--a------] C:\Windows\tasks\SCHEDLGU.TXT

------[ Listing des dossiers dans C:\ProgramData ]------

[20/06/2008|23:49] C:\ProgramData\2 blah
[20/06/2008|23:49] C:\ProgramData\Acid browse htm.5mppsx
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[08/07/2008|01:25] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[20/06/2008|23:49] C:\ProgramData\Hold Trust Amok Mode
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[08/07/2008|19:33] C:\ProgramData\link poke poke.c79cq
[20/06/2008|23:48] C:\ProgramData\link poke poke.doom5nr
[20/06/2008|23:48] C:\ProgramData\link poke poke.dop9zw
[16/06/2008|17:30] C:\ProgramData\link poke poke.h9uygja
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|16:08] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[17/05/2008|14:45] C:\Program Files\EoRezo
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[19/06/2008|22:54] C:\Program Files\ShoppingReport
[13/04/2008|20:52] C:\Program Files\Sitecom
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Common Files ]------

[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller

---------------------------[ Process ]--------------------------

... 61

iexplore.exe ~ [2508]
iexplore.exe ~ [3608]

----------------------[ Recherche avec S_Lop ]---------------------

C:\ProgramData\Acid browse htm.5mppsx
C:\ProgramData\link poke poke.c79cq
C:\ProgramData\link poke poke.doom5nr
C:\ProgramData\link poke poke.dop9zw
C:\ProgramData\link poke poke.h9uygja
C:\ProgramData\link poke poke.c79cq
C:\ProgramData\link poke poke.doom5nr

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\ProgramData\Hold Trust Amok Mode
C:\ProgramData\Hold Trust Amok Mode\pop peak.exe
C:\Windows\Prefetch\POP PEAK.EXE-E2FE624A.pf

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Amok Mode Dupe Platform"="\"C:\\ProgramData\\Acid browse htm.5mppsx\""
"PHONE CORN"="\"C:\\ProgramData\\link poke poke.c79cq\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 20:50:30
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

=> C:\Users\Azdoud\DOCUME~1\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\DOCUME~1\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
=> C:\Users\Azdoud\Documents\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\Documents\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\Music\Musique MP3 de SAID AZDOUD\MP3 3\08-kanye_west-crack_music_(feat_the_game).mp3
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe


[F:151][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:49][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin

[ UAC => 1 ]

--------------------[ Fin du rapport a 20:52:48,69 ]----------------------

------------------------------ Merci
Répondre à Dias_

Re,

Relance Lop S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Par contre, je n'ai pas reussi à >> appuyer simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..." << .
J'ai fait comme precedement, j'ai pressé Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et validé dés que mon Bureau ne réapparaissait pas. C'est normal??? :heink:

Voila le contenu :





-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------

[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 08/07/2008 | 21:18:14,09 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

Supprime! - C:\ProgramData\Hold Trust Amok Mode\pop peak.exe
Supprime! - C:\Windows\Prefetch\POP PEAK.EXE-E2FE624A.pf
Supprime! - C:\ProgramData\Acid browse htm.5mppsx
Supprime! - C:\ProgramData\link poke poke.c79cq
Supprime! - C:\ProgramData\link poke poke.doom5nr
Supprime! - C:\ProgramData\link poke poke.dop9zw
Supprime! - C:\ProgramData\link poke poke.h9uygja
Supprime! - C:\ProgramData\Hold Trust Amok Mode
RestaurÚ! - Fichier Hosts

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\ShoppingReport

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


-------------[ Listing des dossiers dans Roaming ]------------

[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE

[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter

[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec

[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000

[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop

[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth

[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI

[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs


[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}

[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV


[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes

[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004



[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR

[08/07/2008|20:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[08/07/2008|20:50] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials


[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles

[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash

[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore


[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache

[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console


[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion

[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer

----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------

[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[08/07/2008 21:17][--ah-----] C:\Windows\tasks\SA.DAT
[08/07/2008 21:16][--a------] C:\Windows\tasks\SCHEDLGU.TXT

------[ Listing des dossiers dans C:\ProgramData ]------

[20/06/2008|23:49] C:\ProgramData\2 blah
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[08/07/2008|01:25] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|16:08] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[17/05/2008|14:45] C:\Program Files\EoRezo
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[13/04/2008|20:52] C:\Program Files\Sitecom
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Common Files ]------

[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller

---------------------------[ Process ]--------------------------

... 58

... OK !

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 21:19:59
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

=> C:\Users\Azdoud\DOCUME~1\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\DOCUME~1\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
=> C:\Users\Azdoud\Documents\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\Documents\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\Music\Musique MP3 de SAID AZDOUD\MP3 3\08-kanye_west-crack_music_(feat_the_game).mp3
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe


[F:1086][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:57][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin

[ UAC => 1 ]

--------------------[ Fin du rapport a 21:22:17,86 ]----------------------

------------------------------ Merci
Répondre à Dias_

Supprime tes cracks.

 
Citation :

C'est normal??? :heink:


Tu as accès au Bureau ?


Message édité par Angeldark le 08-07-2008 à 21:34:22
------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Citation :

Supprime tes cracks.



euuhhh, c'est à dire??

Citation :

Tu as accès au Bureau ?



oui, j'ai eu accés au bureau.

------------------------------ Merci
Répondre à Dias_

Bah tu supprimes tous tes cracks.
ex : C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin


Message édité par Angeldark le 08-07-2008 à 21:52:52
------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

okok MERCI!! :sweat: désolé je ne suis pas caler en informatique... j'ai supprimer tous ce qu'il y avait dans "Recherche d'autres infections" ... :sarcastic: c'est ça??
je peux desinstaller Lop S&D???


Message édité par Dias_ le 08-07-2008 à 22:12:17
------------------------------ Merci
Répondre à Dias_

Ne le désinstalle pas maintenant.
Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voila le second rapport :


-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------

[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 09/07/2008 | 14:01:50,29 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]

-------------[ Listing des dossiers dans Roaming ]------------

[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE

[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter

[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec

[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000

[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop

[09/07/2008|12:44] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth

[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI

[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs


[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}

[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV


[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes

[09/07/2008|12:39] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004



[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR

[08/07/2008|20:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[08/07/2008|20:50] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials


[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles

[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash

[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG

[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore


[08/07/2008|22:56] C:\Users\Azdoud\AppData\Roaming\TuneUp Software\TuneUp Utilities

[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache

[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console


[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion

[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer

----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------

[09/07/2008 14:01][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[09/07/2008 14:01][--ah-----] C:\Windows\tasks\SA.DAT
[09/07/2008 14:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT

------[ Listing des dossiers dans C:\ProgramData ]------

[20/06/2008|23:49] C:\ProgramData\2 blah
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[09/07/2008|11:42] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[08/07/2008|22:55] C:\ProgramData\TuneUp Software
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|22:54] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[13/04/2008|20:52] C:\Program Files\Sitecom
[08/07/2008|22:56] C:\Program Files\TuneUp Utilities 2008
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Common Files ]------

[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller
[08/07/2008|22:54] C:\Program Files\Common Files\Wise Installation Wizard

---------------------------[ Process ]--------------------------

... 58

... OK !

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 14:03:43
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------


Aucune autre infection trouvée !

[F:326][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:46][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin

[ UAC => 1 ]

--------------------[ Fin du rapport a 14:06:04,64 ]----------------------

------------------------------ Merci
Répondre à Dias_

Angeldark a écrit :

J'ai demandé un Hijackthis.



si cela te va... :p

Logfile of HijackThis v1.99.1
Scan saved at 15:50:44, on 09/07/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Azdoud\AppData\Local\Temp\Temp1_hijackthis[1].zip\HijackThis.exe
c:\program files\google\googletoolbar1user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: (no name) - {46E3F9A7-3313-4F32-A442-D7018F021985} - C:\Users\Azdoud\AppData\Local\Temp\gebabccc.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - (no file)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - (no file)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/re [...] dnl-nl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/bina [...] b57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\Windows\system32\btxppanel.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

------------------------------ Merci
Répondre à Dias_

Il y a des petits restes.

Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec

  • Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
  • Afin de lancer la recherche, clic sur"Rechercher".
  • Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :

-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.

AIDE : Tuto en images sur MBAM

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

OKOK merciii, voila le rapport :

Malwarebytes' Anti-Malware 1.20
Version de la base de données: 933
Windows 6.0.6000

16:56:31 09/07/2008
mbam-log-7-9-2008 (16-56-31).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 216946
Temps écoulé: 30 minute(s), 46 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 24
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 9

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\ProgramData\WildTangent\My HP Game Console\Downloads\fr\Installers\SetupGamesClient.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\5.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.

------------------------------ Merci
Répondre à Dias_

Angeldark a écrit :

Reposte un rapport Hijackthis.



voila le rapport :) :


Logfile of HijackThis v1.99.1
Scan saved at 17:49:21, on 09/07/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\Azdoud\AppData\Local\Temp\Temp2_hijackthis[1].zip\HijackThis.exe
c:\program files\google\googletoolbar1user.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {46E3F9A7-3313-4F32-A442-D7018F021985} - C:\Users\Azdoud\AppData\Local\Temp\gebabccc.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/re [...] dnl-nl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/bina [...] b57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\Windows\system32\btxppanel.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

------------------------------ Merci
Répondre à Dias_

On termine.

Désinstalle correctement Avast! pour le remplacer par AntiVir.
Pourquoi changer ? Avast! vs AntiVir

Fais un scan complet puis poste le rapport en fin d'analyse.
AIDE : Tutorial sur l'antivirus AntiVir Personal Edition Classic

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Enfait, j'ai eu quelques problemes avec l'installation de l'anti-virus "Antivir".
l'autre jour, j'avais installer "antivir" et lors du scan, plusieurs virus ont eté trouvé mais je n'arrivais pas à les supprimer ni a les mettre en Quarantaine ... :(
et ils revennais tous le temps ... :??:

------------------------------ Merci
Répondre à Dias_

Tu faisais le scan en sans échec ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Angeldark a écrit :

Tu faisais le scan en sans échec ?




Non, c'etait hier, avant le scan en mode sans echec !! et là ma tour fait un drole de bruit :??:

------------------------------ Merci
Répondre à Dias_

Ce n'est pas lié à l'infection le bruit. Je te parle du mode sans échec et Antivir.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Angeldark a écrit :

Ce n'est pas lié à l'infection le bruit. Je te parle du mode sans échec et Antivir.



Citation :


Tu faisais le scan en sans échec ?



Non, je ne faisait pas le scan en sans echec :sweat:

------------------------------ Merci
Répondre à Dias_

Bonsoir,

Je reprends le sujet, Angeldark étant en vacances.

Fais un scan en mode sans échec, et poste le rapport ici.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

Citation :

Bonsoir,

Je reprends le sujet, Angeldark étant en vacances.



Salut XmichouX, mon probleme étant je pense résolu grace à Angeldark, mais il m'a demandé d'intaller "antivir" pour lui poster un rapport!!. je reste un peu méfiant par rapport a cet anti-virus parceque l'autre jour l'ayant installer, j'ai eu quelques problemes (des pages signalant que j'ai un virus venaient, mais je ne pouvais ni le supprimer ni le mettre en quarantaine...) :??:


Message édité par Dias_ le 10-07-2008 à 15:08:32
------------------------------ Merci
Répondre à Dias_

Il n'est en aucun cas dangereux :)
Essaie le scan en mode sans échec ;) Et poste le rapport.

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

XmichouX a écrit :

Il n'est en aucun cas dangereux :)
Essaie le scan en mode sans échec ;) Et poste le rapport.




Okok je desinstale "avast" et je fais le scan ... :ange:

------------------------------ Merci
Répondre à Dias_

Ne t'inquiète pas :)

------------------------------ >> Centre de Formation Helpers <<
Répondre à XmichouX

sinon j' ai plus rapide

Désinstalle Live messenger + tu l' aura plus
Et réinstalle le sans le sponsor ni a l' amelioration.

Répondre à wowane72
Tom's Guide > Forum > Sécurité - Virus > CiD sous Vista
Aller à :

Il y a 533 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens