CiD sous Vista
Forum Sécurité - Virus : CiD sous Vista
Salut,
Depuis 2 mois, je recois des Pubs nomées CiD lorsque j'ouvre une page internet. j'ai deja verifié et ce n'est pas à cause de MSN Live +. je ne sais vraiment plus quoi faire......
quelqu'un peu m'aider à le supprimer svp!
Message édité par Dias_ le 08-07-2008 à 18:58:30
Bonjour,
Télécharge Lop S&D.exe (Eric_71) sur ton Bureau.
- Lance l'installation du programme en exécutant le fichier téléchargé.
- Double-clique maintenant sur le raccourci de LopS&D.
- Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
- Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
- Poste le rapport généré (C:\lopR.txt*)
(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
* le nom de la partition peut changer
Répondre à Angeldark
Merci, j’ai suivi ton conseil on ma demander « d’exécuter en tant qu’administrateur » et apres un redémarrage de mon ordinateur et apres la recherche on m’affiche ce qui suit :
-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 08/07/2008 | 20:48:00,49 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]
-------------[ Listing des dossiers dans Roaming ]------------
[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE
[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter
[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec
[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop
[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth
[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}
[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV
[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes
[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004
[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[08/07/2008|15:14] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials
[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles
[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash
[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore
[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console
[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[08/07/2008 20:47][--ah-----] C:\Windows\tasks\SA.DAT
[08/07/2008 20:46][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[20/06/2008|23:49] C:\ProgramData\2 blah
[20/06/2008|23:49] C:\ProgramData\Acid browse htm.5mppsx
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[08/07/2008|01:25] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[20/06/2008|23:49] C:\ProgramData\Hold Trust Amok Mode
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[08/07/2008|19:33] C:\ProgramData\link poke poke.c79cq
[20/06/2008|23:48] C:\ProgramData\link poke poke.doom5nr
[20/06/2008|23:48] C:\ProgramData\link poke poke.dop9zw
[16/06/2008|17:30] C:\ProgramData\link poke poke.h9uygja
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|16:08] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[17/05/2008|14:45] C:\Program Files\EoRezo
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[19/06/2008|22:54] C:\Program Files\ShoppingReport
[13/04/2008|20:52] C:\Program Files\Sitecom
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 61
iexplore.exe ~ [2508]
iexplore.exe ~ [3608]
----------------------[ Recherche avec S_Lop ]---------------------
C:\ProgramData\Acid browse htm.5mppsx
C:\ProgramData\link poke poke.c79cq
C:\ProgramData\link poke poke.doom5nr
C:\ProgramData\link poke poke.dop9zw
C:\ProgramData\link poke poke.h9uygja
C:\ProgramData\link poke poke.c79cq
C:\ProgramData\link poke poke.doom5nr
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\ProgramData\Hold Trust Amok Mode
C:\ProgramData\Hold Trust Amok Mode\pop peak.exe
C:\Windows\Prefetch\POP PEAK.EXE-E2FE624A.pf
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Amok Mode Dupe Platform"="\"C:\\ProgramData\\Acid browse htm.5mppsx\""
"PHONE CORN"="\"C:\\ProgramData\\link poke poke.c79cq\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 20:50:30
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Users\Azdoud\DOCUME~1\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\DOCUME~1\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
=> C:\Users\Azdoud\Documents\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\Documents\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\Music\Musique MP3 de SAID AZDOUD\MP3 3\08-kanye_west-crack_music_(feat_the_game).mp3
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
[F:151][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:49][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 20:52:48,69 ]----------------------
Répondre à Dias_
Re,
Relance Lop S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Répondre à Angeldark
Par contre, je n'ai pas reussi à >> appuyer simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..." << .
J'ai fait comme precedement, j'ai pressé Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et validé dés que mon Bureau ne réapparaissait pas. C'est normal???
Voila le contenu :
-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 08/07/2008 | 21:18:14,09 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprime! - C:\ProgramData\Hold Trust Amok Mode\pop peak.exe
Supprime! - C:\Windows\Prefetch\POP PEAK.EXE-E2FE624A.pf
Supprime! - C:\ProgramData\Acid browse htm.5mppsx
Supprime! - C:\ProgramData\link poke poke.c79cq
Supprime! - C:\ProgramData\link poke poke.doom5nr
Supprime! - C:\ProgramData\link poke poke.dop9zw
Supprime! - C:\ProgramData\link poke poke.h9uygja
Supprime! - C:\ProgramData\Hold Trust Amok Mode
RestaurÚ! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Supprime! - C:\Program Files\ShoppingReport
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Roaming ]------------
[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE
[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter
[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec
[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop
[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth
[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}
[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV
[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes
[08/07/2008|20:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004
[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR
[08/07/2008|20:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[08/07/2008|20:50] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials
[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles
[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash
[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore
[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console
[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[08/07/2008 21:17][--ah-----] C:\Windows\tasks\SA.DAT
[08/07/2008 21:16][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[20/06/2008|23:49] C:\ProgramData\2 blah
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[08/07/2008|01:25] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|16:08] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[17/05/2008|14:45] C:\Program Files\EoRezo
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[13/04/2008|20:52] C:\Program Files\Sitecom
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 58
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-08 21:19:59
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> C:\Users\Azdoud\DOCUME~1\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\DOCUME~1\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\DOCUME~1\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
=> C:\Users\Azdoud\Documents\Kamel\Nouveau dossier\Psy4 De La Rime - Ma cit‚ va cracker.mp3
=> C:\Users\Azdoud\Documents\mah usb\Virtual Dj v2.01 Full + Effects + Skins [ by DJ Francky ]\VirtualDJ v2.01 - Crack.exe
=> C:\Users\Azdoud\Music\Musique MP3 de SAID AZDOUD\MP3 3\08-kanye_west-crack_music_(feat_the_game).mp3
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\InCD40121.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Keygen-Nero.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NBR60011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\Nero60011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroMix1404.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNet1.0.43.0RC1.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NeroNMP1405.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NMP1405FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\NVE2011FRA.exe
=> C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\ultime plug in nero6.exe
[F:1086][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:57][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 21:22:17,86 ]----------------------
Répondre à Dias_
Supprime tes cracks.
| Citation : C'est normal??? |
Tu as accès au Bureau ?
Message édité par Angeldark le 08-07-2008 à 21:34:22
Répondre à Angeldark
| Citation : Supprime tes cracks. |
euuhhh, c'est à dire??
| Citation : Tu as accès au Bureau ? |
oui, j'ai eu accés au bureau.
Répondre à Dias_
Bah tu supprimes tous tes cracks.
ex : C:\Users\Azdoud\Documents\mah usb\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin
Message édité par Angeldark le 08-07-2008 à 21:52:52
Répondre à Angeldark
okok MERCI!!
désolé je ne suis pas caler en informatique... j'ai supprimer tous ce qu'il y avait dans "Recherche d'autres infections" ...
c'est ça??
je peux desinstaller Lop S&D???
Message édité par Dias_ le 08-07-2008 à 22:12:17
Répondre à Dias_
Ne le désinstalle pas maintenant.
Reposte un rapport Hijackthis.
Répondre à Angeldark
Voila le second rapport :
-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Azdoud ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 09/07/2008 | 14:01:50,29 ] [ PC : PC-DE-AZDOUD ]
[ MAJ : 06-07-2008 | 10:55 ]
[ UAC => 0 ]
-------------[ Listing des dossiers dans Roaming ]------------
[10/04/2008|15:32] C:\Users\Azdoud\AppData\Roaming\Adobe\Flash Player
[13/03/2008|17:37] C:\Users\Azdoud\AppData\Roaming\Adobe\Linguistics
[13/03/2008|17:36] C:\Users\Azdoud\AppData\Roaming\Adobe\Acrobat
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\ATI\ACE
[13/04/2008|16:38] C:\Users\Azdoud\AppData\Roaming\CyberLink\MediaCache
[02/03/2008|16:02] C:\Users\Azdoud\AppData\Roaming\CyberLink\PowerStarter
[19/05/2008|12:15] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Player
[19/05/2008|01:44] C:\Users\Azdoud\AppData\Roaming\DivX\DivX Codec
[29/06/2008|14:44] C:\Users\Azdoud\AppData\Roaming\dvdcss\SKPGY-2006082616305200
[29/06/2008|14:38] C:\Users\Azdoud\AppData\Roaming\dvdcss\BAAZIGAR-2006072621150000
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\db
[17/05/2008|14:43] C:\Users\Azdoud\AppData\Roaming\EoRezo\eoDesktop
[09/07/2008|12:44] C:\Users\Azdoud\AppData\Roaming\Google\Local Search History
[22/04/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Google\GoogleEarth
[12/03/2008|13:10] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HPAdvisor
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Hewlett-Packard\HP Software UI
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\Digital Imaging
[14/05/2008|19:33] C:\Users\Azdoud\AppData\Roaming\HP\ScLogs
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Identities\{000HQ7FF-AD7A-3FG5-BPAV-24QJBB1JIVUR}
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Identities\{B39EA25A-F1A2-4175-8394-0CF429FBA846}
[17/05/2008|16:07] C:\Users\Azdoud\AppData\Roaming\ItsLabel\ItsTV
[23/04/2008|17:32] C:\Users\Azdoud\AppData\Roaming\LimeWire\xml
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\.AppSpecialShare
[23/04/2008|17:22] C:\Users\Azdoud\AppData\Roaming\LimeWire\themes
[09/07/2008|12:39] C:\Users\Azdoud\AppData\Roaming\Macromedia\Flash Player
[20/04/2008|19:26] C:\Users\Azdoud\AppData\Roaming\Macromedia\Director MX 2004
[03/06/2008|17:57] C:\Users\Azdoud\AppData\Roaming\Micro Application\CDR
[08/07/2008|20:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\preuve
[08/07/2008|20:50] C:\Users\Azdoud\AppData\Roaming\Microsoft\ModŠles
[08/07/2008|15:58] C:\Users\Azdoud\AppData\Roaming\Microsoft\Word
[02/07/2008|18:25] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Photo Gallery
[30/06/2008|16:20] C:\Users\Azdoud\AppData\Roaming\Microsoft\MSN Messenger
[28/06/2008|18:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Services Windows Live
[06/06/2008|18:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Crypto
[17/05/2008|14:45] C:\Users\Azdoud\AppData\Roaming\Microsoft\Installer
[11/05/2008|21:42] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows Live Call
[16/04/2008|17:47] C:\Users\Azdoud\AppData\Roaming\Microsoft\Office
[14/04/2008|13:49] C:\Users\Azdoud\AppData\Roaming\Microsoft\IdentityCRL
[27/03/2008|19:55] C:\Users\Azdoud\AppData\Roaming\Microsoft\Internet Explorer
[27/03/2008|19:02] C:\Users\Azdoud\AppData\Roaming\Microsoft\Network
[27/03/2008|18:51] C:\Users\Azdoud\AppData\Roaming\Microsoft\HTML Help
[14/03/2008|19:18] C:\Users\Azdoud\AppData\Roaming\Microsoft\Media Catalog
[13/03/2008|21:22] C:\Users\Azdoud\AppData\Roaming\Microsoft\PowerPoint
[13/03/2008|19:43] C:\Users\Azdoud\AppData\Roaming\Microsoft\Macros compl‚mentaires
[07/03/2008|16:21] C:\Users\Azdoud\AppData\Roaming\Microsoft\Windows
[02/03/2008|13:12] C:\Users\Azdoud\AppData\Roaming\Microsoft\Works
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\Templates
[02/03/2008|13:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\UProof
[02/03/2008|13:00] C:\Users\Azdoud\AppData\Roaming\Microsoft\eHome
[01/03/2008|22:08] C:\Users\Azdoud\AppData\Roaming\Microsoft\Protect
[01/03/2008|22:06] C:\Users\Azdoud\AppData\Roaming\Microsoft\CLR Security Config
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\SystemCertificates
[01/03/2008|22:04] C:\Users\Azdoud\AppData\Roaming\Microsoft\Credentials
[13/04/2008|16:52] C:\Users\Azdoud\AppData\Roaming\muvee Technologies\UserProfiles
[06/07/2008|15:15] C:\Users\Azdoud\AppData\Roaming\PlayFirst\5thGrader
[20/04/2008|20:12] C:\Users\Azdoud\AppData\Roaming\PlayFirst\Dr. Daisy Pet Vet
[09/03/2008|13:03] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash2
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\PlayFirst\dinerdash
[05/05/2008|19:22] C:\Users\Azdoud\AppData\Roaming\ReaSoft\ReaJPEG
[01/03/2008|22:09] C:\Users\Azdoud\AppData\Roaming\Symantec\NPMDataStore
[08/07/2008|22:56] C:\Users\Azdoud\AppData\Roaming\TuneUp Software\TuneUp Utilities
[12/04/2008|20:43] C:\Users\Azdoud\AppData\Roaming\vlc\cache
[02/03/2008|16:43] C:\Users\Azdoud\AppData\Roaming\WildTangent\My HP Game Console
[09/04/2008|15:10] C:\Users\Azdoud\AppData\Roaming\Yahoo!\Companion
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\46
[09/04/2008|14:12] C:\Users\Azdoud\AppData\Roaming\Zylom\ZylomGamesPlayer
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[09/07/2008 14:01][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[06/07/2008 18:00][--a------] C:\Windows\tasks\Norton Security Scan.job
[08/07/2008 15:56][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{11EE2DEA-4247-41B8-8AF7-380D06AEF80E}.job
[09/07/2008 14:01][--ah-----] C:\Windows\tasks\SA.DAT
[09/07/2008 14:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[20/06/2008|23:49] C:\ProgramData\2 blah
[30/03/2008|16:14] C:\ProgramData\Adobe
[27/05/2008|18:28] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[06/03/2008|12:09] C:\ProgramData\Arcade Lab
[08/12/2007|02:14] C:\ProgramData\ATI
[08/07/2008|19:47] C:\ProgramData\Avira
[18/04/2008|14:43] C:\ProgramData\BOONTY
[01/03/2008|22:00] C:\ProgramData\Bureau
[02/03/2008|16:02] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[17/05/2008|13:43] C:\ProgramData\Downloaded Installations
[01/03/2008|22:00] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[30/03/2008|20:24] C:\ProgramData\Google
[09/07/2008|11:42] C:\ProgramData\Google Updater
[13/03/2008|19:33] C:\ProgramData\Hewlett-Packard
[14/05/2008|19:30] C:\ProgramData\HP
[14/05/2008|19:22] C:\ProgramData\HP Product Assistant
[14/05/2008|19:24] C:\ProgramData\HPSSUPPLY
[14/05/2008|19:32] C:\ProgramData\hpzinstall.log
[06/03/2008|12:32] C:\ProgramData\InterAction studios
[27/03/2008|18:08] C:\ProgramData\LuUninstall.LiveUpdate
[01/03/2008|22:00] C:\ProgramData\Menu D‚marrer
[08/07/2008|17:32] C:\ProgramData\Messenger Plus!
[27/03/2008|18:51] C:\ProgramData\Microsoft
[01/03/2008|22:00] C:\ProgramData\ModŠles
[08/12/2007|02:24] C:\ProgramData\muvee Technologies
[08/12/2007|02:30] C:\ProgramData\PC-Doctor
[05/07/2008|17:09] C:\ProgramData\pixelStorm
[06/07/2008|15:14] C:\ProgramData\PlayFirst
[02/11/2006|15:02] C:\ProgramData\Start Menu
[27/03/2008|18:15] C:\ProgramData\Symantec
[09/04/2008|14:39] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[08/07/2008|22:55] C:\ProgramData\TuneUp Software
[14/05/2008|19:32] C:\ProgramData\WEBREG
[22/03/2008|15:24] C:\ProgramData\WildTangent
[16/06/2008|17:20] C:\ProgramData\WLInstaller
[09/04/2008|14:12] C:\ProgramData\Zylom
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[07/07/2008|16:23] C:\Program Files\Adobe
[27/03/2008|18:22] C:\Program Files\Alwil Software
[08/12/2007|02:09] C:\Program Files\ATI
[08/12/2007|02:10] C:\Program Files\ATI Technologies
[23/04/2008|19:35] C:\Program Files\BoontyGames
[31/03/2008|19:51] C:\Program Files\CCleaner
[08/07/2008|22:54] C:\Program Files\Common Files
[08/12/2007|02:23] C:\Program Files\CyberLink
[08/12/2007|01:52] C:\Program Files\desktop.ini
[19/05/2008|00:27] C:\Program Files\DivX
[06/07/2008|14:27] C:\Program Files\Dofus
[08/12/2007|09:44] C:\Program Files\EasyBits
[02/03/2008|16:00] C:\Program Files\EasyBits For Kids
[01/03/2008|22:00] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[04/07/2008|19:17] C:\Program Files\GameSpy Arcade
[22/04/2008|19:10] C:\Program Files\Google
[08/12/2007|02:32] C:\Program Files\Hewlett-Packard
[14/05/2008|19:24] C:\Program Files\HP
[06/07/2008|15:13] C:\Program Files\HP Games
[05/05/2008|19:21] C:\Program Files\ImagePrinter
[13/04/2008|19:21] C:\Program Files\InstallShield Installation Information
[11/06/2008|15:53] C:\Program Files\Internet Explorer
[08/12/2007|02:26] C:\Program Files\Java
[05/05/2008|19:15] C:\Program Files\JpgRenamer
[23/04/2008|17:22] C:\Program Files\LimeWire
[08/07/2008|17:12] C:\Program Files\Messenger Plus! Live
[03/06/2008|18:38] C:\Program Files\Micro Application
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[13/03/2008|19:38] C:\Program Files\Microsoft Office
[08/12/2007|02:27] C:\Program Files\Microsoft Works
[08/12/2007|10:00] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[16/05/2008|12:48] C:\Program Files\MSXML 4.0
[06/07/2008|18:00] C:\Program Files\Norton Security Scan
[08/07/2008|18:51] C:\Program Files\Panda Security
[03/05/2008|20:33] C:\Program Files\PC Camera
[08/12/2007|02:46] C:\Program Files\PC-Doctor 5 for Windows
[07/07/2008|20:09] C:\Program Files\PCHealthCenter
[17/05/2008|15:12] C:\Program Files\QuickTime
[08/12/2007|02:12] C:\Program Files\Realtek
[05/05/2008|19:22] C:\Program Files\ReaSoft
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[08/12/2007|02:36] C:\Program Files\Services en ligne
[13/04/2008|20:52] C:\Program Files\Sitecom
[08/07/2008|22:56] C:\Program Files\TuneUp Utilities 2008
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[28/03/2008|21:52] C:\Program Files\VideoLAN
[09/03/2008|18:23] C:\Program Files\VirtualDJ
[08/12/2007|10:31] C:\Program Files\Windows Calendar
[08/12/2007|10:00] C:\Program Files\Windows Collaboration
[08/12/2007|10:10] C:\Program Files\Windows Defender
[08/12/2007|10:00] C:\Program Files\Windows Journal
[16/06/2008|17:24] C:\Program Files\Windows Live
[11/06/2008|15:53] C:\Program Files\Windows Mail
[08/12/2007|10:42] C:\Program Files\Windows Media Player
[01/03/2008|22:00] C:\Program Files\Windows NT
[08/12/2007|10:00] C:\Program Files\Windows Photo Gallery
[28/03/2008|20:03] C:\Program Files\Windows Sidebar
[19/05/2008|18:30] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[30/03/2008|16:14] C:\Program Files\Common Files\Adobe
[08/07/2008|16:27] C:\Program Files\Common Files\BitDefender
[18/04/2008|14:43] C:\Program Files\Common Files\BOONTY Shared
[13/03/2008|19:28] C:\Program Files\Common Files\Designer
[14/05/2008|19:21] C:\Program Files\Common Files\Hewlett-Packard
[08/12/2007|02:15] C:\Program Files\Common Files\HP
[08/12/2007|02:43] C:\Program Files\Common Files\InstallShield
[08/12/2007|02:25] C:\Program Files\Common Files\Java
[08/12/2007|02:24] C:\Program Files\Common Files\LightScribe
[08/12/2007|02:23] C:\Program Files\Common Files\LS Getting Started
[27/03/2008|20:10] C:\Program Files\Common Files\microsoft shared
[19/05/2008|00:27] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/07/2008|09:57] C:\Program Files\Common Files\Symantec Shared
[08/12/2007|10:16] C:\Program Files\Common Files\System
[27/03/2008|20:09] C:\Program Files\Common Files\WindowsLiveInstaller
[08/07/2008|22:54] C:\Program Files\Common Files\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 58
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 14:03:43
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
[F:326][D:17]-> C:\Users\Azdoud\AppData\Local\Temp
[F:46][D:1]-> C:\Users\Azdoud\AppData\Roaming\MICROS~1\Windows\Cookies
[F:5][D:5]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 14:06:04,64 ]----------------------
Répondre à Dias_
J'ai demandé un Hijackthis.
Répondre à Angeldark
| Angeldark a écrit : J'ai demandé un Hijackthis. |
si cela te va...
Logfile of HijackThis v1.99.1
Scan saved at 15:50:44, on 09/07/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Azdoud\AppData\Local\Temp\Temp1_hijackthis[1].zip\HijackThis.exe
c:\program files\google\googletoolbar1user.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
O2 - BHO: (no name) - {46E3F9A7-3313-4F32-A442-D7018F021985} - C:\Users\Azdoud\AppData\Local\Temp\gebabccc.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - (no file)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - (no file)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/re [...] dnl-nl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/bina [...] b57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\Windows\system32\btxppanel.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Répondre à Dias_
Il y a des petits restes.
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
- Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
- Afin de lancer la recherche, clic sur"Rechercher".
- Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.
AIDE : Tuto en images sur MBAM
Répondre à Angeldark
OKOK merciii, voila le rapport :
Malwarebytes' Anti-Malware 1.20
Version de la base de données: 933
Windows 6.0.6000
16:56:31 09/07/2008
mbam-log-7-9-2008 (16-56-31).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 216946
Temps écoulé: 30 minute(s), 46 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 24
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 9
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\ProgramData\WildTangent\My HP Game Console\Downloads\fr\Installers\SetupGamesClient.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\5.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
Répondre à Dias_
Reposte un rapport Hijackthis.
Répondre à Angeldark
| Angeldark a écrit : Reposte un rapport Hijackthis. |
voila le rapport
:
Logfile of HijackThis v1.99.1
Scan saved at 17:49:21, on 09/07/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\Azdoud\AppData\Local\Temp\Temp2_hijackthis[1].zip\HijackThis.exe
c:\program files\google\googletoolbar1user.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr? [...] pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {46E3F9A7-3313-4F32-A442-D7018F021985} - C:\Users\Azdoud\AppData\Local\Temp\gebabccc.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/re [...] dnl-nl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/bina [...] b57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\Windows\system32\btxppanel.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Répondre à Dias_
On termine.
Désinstalle correctement Avast! pour le remplacer par AntiVir.
Pourquoi changer ? Avast! vs AntiVir
Fais un scan complet puis poste le rapport en fin d'analyse.
AIDE : Tutorial sur l'antivirus AntiVir Personal Edition Classic
Répondre à Angeldark
Enfait, j'ai eu quelques problemes avec l'installation de l'anti-virus "Antivir".
l'autre jour, j'avais installer "antivir" et lors du scan, plusieurs virus ont eté trouvé mais je n'arrivais pas à les supprimer ni a les mettre en Quarantaine ...
et ils revennais tous le temps ...
Répondre à Dias_
Tu faisais le scan en sans échec ?
Répondre à Angeldark
| Angeldark a écrit : Tu faisais le scan en sans échec ? |
Non, c'etait hier, avant le scan en mode sans echec !! et là ma tour fait un drole de bruit
Répondre à Dias_
Ce n'est pas lié à l'infection le bruit. Je te parle du mode sans échec et Antivir.
Répondre à Angeldark
| Angeldark a écrit : Ce n'est pas lié à l'infection le bruit. Je te parle du mode sans échec et Antivir. |
| Citation :
|
Non, je ne faisait pas le scan en sans echec
Répondre à Dias_
Bonsoir,
Je reprends le sujet, Angeldark étant en vacances.
Fais un scan en mode sans échec, et poste le rapport ici.
Répondre à XmichouX
| Citation : Bonsoir,
|
Salut XmichouX, mon probleme étant je pense résolu grace à Angeldark, mais il m'a demandé d'intaller "antivir" pour lui poster un rapport!!. je reste un peu méfiant par rapport a cet anti-virus parceque l'autre jour l'ayant installer, j'ai eu quelques problemes (des pages signalant que j'ai un virus venaient, mais je ne pouvais ni le supprimer ni le mettre en quarantaine...)
Message édité par Dias_ le 10-07-2008 à 15:08:32
Répondre à Dias_
Il n'est en aucun cas dangereux
Essaie le scan en mode sans échec
Et poste le rapport.
Répondre à XmichouX
| XmichouX a écrit : Il n'est en aucun cas dangereux |
Okok je desinstale "avast" et je fais le scan ...
Répondre à Dias_
Ne t'inquiète pas
Répondre à XmichouX
sinon j' ai plus rapide
Désinstalle Live messenger + tu l' aura plus
Et réinstalle le sans le sponsor ni a l' amelioration.
Il y a 533 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
