Fenêtres pub

BigManUtd -  
loloetseb Messages postés 5684 Statut Membre -
Bonjour,
j'ai des fenêtres de pub qui s'ouvrent
j'ai mozilla comme navigateur
et j'ai avast comme anti-virus

comment faire pour les supprimer ?
A voir également:

85 réponses

loloetseb Messages postés 5684 Statut Membre 174
 
alut,

Peux tu faire un scan hijack this,

Fais "do a scan and save a log",copies le rapport (ctrl+c) et postes le (ctrl+v) sur cette page

http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
0
BigManUtd
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:54:31, on 08/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sports.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [Youtube] C:\Program Files\Youtube\Youtube.exe
O4 - HKLM\..\Run: [bait deaf idle setup] C:\Documents and Settings\All Users\Application Data\Htm Support Bait Deaf\dead scr.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P36 "EPSON Stylus CX3600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX3600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Proc Deaf Delete Peak] C:\Documents and Settings\All Users\Application Data\file joy proc deaf\01 extra.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Peak new] C:\DOCUME~1\Danny\APPLIC~1\FIVEBO~1\closemfcd.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Youtube.lnk = C:\Program Files\Youtube\Youtube.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZCxdm490YYLU
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
0
loloetseb Messages postés 5684 Statut Membre 174
 
1)Télécharge Toolbar-S&D (Team IDN) sur ton Bureau :

https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option "1" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
0
BigManUtd
 
j'ai téléchargé les programme, je l'ai lancé, j'ai tapé 1, et là, il y a " Recherche de Fichiers / Dossiers ... "
le programme est bloqué, ou c'est comme ça ?
0
BigManUtd
 
ah bah voilà, c'est bon

rapport:

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology ML-32 )
BIOS : Ver 1.00PARTTBLh
USER : Danny ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090207-0] 4.8.1296 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:53 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 08/02/2009|15:00 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\DOCUME~1\Danny\Cookies\danny@antivirusgolden[1].txt
C:\DOCUME~1\Danny\Cookies\danny@code-crawler[2].txt
C:\DOCUME~1\Danny\Cookies\danny@hotbar[2].txt
C:\DOCUME~1\Danny\Cookies\danny@myway[1].txt
C:\DOCUME~1\Danny\Cookies\danny@mywebsearch[1].txt
C:\DOCUME~1\Danny\Cookies\danny@h.starware[1].txt
C:\DOCUME~1\Danny\Cookies\danny@try.starware[1].txt
C:\DOCUME~1\Danny\LOCALS~1\Temp\ICD1.tmp

-----------\\ Extensions

(Danny) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Danny) - {7E77F5DF-8022-40e3-9122-F03DEBEFC43B} => psicotsi
(Danny) - {90ab4b7a-dfc8-420b-a205-eae16593e719} => skillraise
(Danny) - {9d1f059c-cada-4111-9696-41a62d64e3ba} => foxtrick

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sports.fr/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchAssistant"="http://search.bearshare.com/sidebar.html?src=ssb"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page"="https://fr.yahoo.com/"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game

1 - "C:\ToolBar SD\TB_1.txt" - 08/02/2009|15:08 - Option : [1]

-----------\\ Fin du rapport a 15:08:11,70
0
loloetseb Messages postés 5684 Statut Membre 174
 
Relances toolbar sd,puis 2 et postes moi le rapport.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
loloetseb Messages postés 5684 Statut Membre 174
 
Ensuite:

Télécharge de AD-Remover de Cyrildu17 / C_XX) sur ton Bureau.

http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

/!\ Déconnecte-toi et ferme toutes applications en cours /!\

- Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
- Double-clique sur l'icône Ad-remover située sur ton Bureau.
- Au menu principal, choisis l'option "A".
- Poste le rapport qui apparaît à la fin.

(Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

Note :

"Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
BigManUtd
 
-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology ML-32 )
BIOS : Ver 1.00PARTTBLh
USER : Danny ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090207-0] 4.8.1296 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:53 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 08/02/2009|15:18 )

-----------\\ SUPPRESSION

Supprime! - C:\DOCUME~1\Danny\Cookies\danny@antivirusgolden[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@code-crawler[2].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@hotbar[2].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@myway[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@mywebsearch[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@h.starware[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@try.starware[1].txt
Supprime! - C:\DOCUME~1\Danny\LOCALS~1\Temp\ICD1.tmp

-----------\\ Recherche de Fichiers / Dossiers ...

-----------\\ Extensions

(Danny) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Danny) - {7E77F5DF-8022-40e3-9122-F03DEBEFC43B} => psicotsi
(Danny) - {90ab4b7a-dfc8-420b-a205-eae16593e719} => skillraise
(Danny) - {9d1f059c-cada-4111-9696-41a62d64e3ba} => foxtrick

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sports.fr/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchAssistant"="http://search.bearshare.com/sidebar.html?src=ssb"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page"="https://www.msn.com/fr-fr/"

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game

1 - "C:\ToolBar SD\TB_1.txt" - 08/02/2009|15:08 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 08/02/2009|15:23 - Option : [2]

-----------\\ Fin du rapport a 15:23:42,84
0
loloetseb Messages postés 5684 Statut Membre 174
 
Je te conseille vivement de supprimer tes cracks sinon l'infection va se reinstaller

Cracks & Keygens ..

C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game

Ensuite,fais ad remover comme indiqué sur le post 7
0
BigManUtd
 
je les supprime dans ces emplacements ?
comment je l'ai eu, ces cracks ?

le rapport de Ad-Remover
0
loloetseb Messages postés 5684 Statut Membre 174
 
C'est un jeu cracké non?Sinon tu les a peut etre eu sur des jeux en ligne

frontier_town\

Ensuite fait ad remover et poste moi le rapport
0
BigManUtd
 
ouais, je joue/jouais pas mal de fois en ligne :s

att je vais supprimer les cracks

je fais quoi après ?

-frontier_town, c'est quoi ?
0
loloetseb Messages postés 5684 Statut Membre 174
 
-frontier_town, c'est quoi ?

C'est le jeu ou ce trouve le crack (a priori,jeux en ligne,tu as l'infection dedans,surement boonty)

Ensuite fait ad remover et poste moi le rapport (tu a la procedure dans le post 7)
0
BigManUtd
 
ah ok

j'arrive pas à trouver ces emplacement !
je vais sur disque dur, mais je trouve le /DOCUME~1/ c'est pas Doucments an settings ?
0
BigManUtd > BigManUtd
 
att je me suis trompé, j'ai oublié le 'pas' sur mais je trouve le /DOCUME~1/
je trouve pas le /DOCUME~1/
0
loloetseb Messages postés 5684 Statut Membre 174
 
Bon c'est pa grave,on fera plus tard ,fais ad remover option A et postes moi le rapport
0
loloetseb Messages postés 5684 Statut Membre 174
 
Fais ad remover
0
BigManUtd
 
------- LOGFILE OF AD-REMOVER 1.1.0.9 | ONLY XP/VISTA -------

Updated by C_XX on 07/02/2009 at 14:30

Start at: 15:33:43 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 48

+--------------------| Boonty/Boonty Games Elements Found:

.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt

+--------------------| Eorezo Elements Found:

.

+--------------------| Infected Poker Softwares Elements Found:

HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\Everest Poker\data
C:\Program Files\Everest Poker\history
C:\Program Files\Everest Poker\data\fonts
C:\Program Files\Everest Poker\data\mp-lobby
C:\Program Files\Everest Poker\data\mp-poker
C:\Program Files\Everest Poker\data\shared
C:\Program Files\Everest Poker\data\startup
C:\Program Files\Everest Poker\data\mp-poker\background
C:\Program Files\Everest Poker\data\mp-poker\fr
C:\Program Files\Everest Poker\data\shared\fr
C:\Program Files\Everest Poker\data\shared\shared
C:\Program Files\Everest Poker\data\shared\shared\bitmaps
C:\Program Files\Everest Poker\data\shared\shared\sounds
C:\Program Files\Everest Poker\data\startup\en
C:\Program Files\Everest Poker\data\startup\fr
C:\Program Files\Everest Poker\data\startup\shared
C:\Program Files\Everest Poker\data\startup\shared\bitmaps
C:\Program Files\Everest Poker\data\startup\shared\icons
C:\Program Files\Everest Poker\data\startup\shared\sounds
C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\images
C:\Program Files\PartyGaming\Language
C:\Program Files\PartyGaming\PartyCasino
C:\Program Files\PartyGaming\PartyPoker
C:\Program Files\PartyGaming\tmpUpgrade
C:\Program Files\PartyGaming\Language\en_US
C:\Program Files\PartyGaming\Language\fr_FR
C:\Program Files\PartyGaming\Language\en_US\temp
C:\Program Files\PartyGaming\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyCasino\Images
C:\Program Files\PartyGaming\PartyCasino\Language
C:\Program Files\PartyGaming\PartyCasino\Temp
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE
C:\Program Files\PartyGaming\PartyCasino\Language\en_US
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE\images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\articles
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\lobby
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyPoker\Images
C:\Program Files\PartyGaming\PartyPoker\Language
C:\Program Files\PartyGaming\PartyPoker\NewSounds
C:\Program Files\PartyGaming\PartyPoker\PokerTrainer
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade
C:\Program Files\PartyGaming\PartyPoker\Images\NewGameTable
C:\Program Files\PartyGaming\PartyPoker\Language\en_US
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images\NewGameTable
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt

+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Found:

.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt

+--------------------| It's TV Elements Found:

.

+--------------------| Sweetim Elements Found:

HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
.

+--------------------| Added Scan:

---- Mozilla FireFox Version 3.0.6 ----

ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.

---- Internet Explorer Version 6.0.2900.2180 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr

+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]

SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.google.com
Start page: hxxp:/www.msn.com

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp:/ieframe.dll

+---------------------------------------------------------------------------+

[~7360 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-

End at: 15:37:01 | 08/02/2009
.
+--------------------| E.O.F - 142 Lines
.
0
loloetseb Messages postés 5684 Statut Membre 174
 
Relances ad remover,fais A,puis cliques sur 1,3,4,6 puis S et postes moi le rapport.Tu es tres infecté,va falloir arretter de jouer en ligne sur des sites frauduleux!!!!
0
BigManUtd
 
oh là
jeux en ligne, c'est les jeux comme jeux.fr armorgames.com ou des jeux comme hattrick.org ?

j'ai lancé ad-remover, j'ai tapé A et enter, mais je sais pas où je dois cliquer 1,3,4,6 et S
0
loloetseb Messages postés 5684 Statut Membre 174
 
Ensuite

1)Télécharge Toolbar-S&D (Team IDN) sur ton Bureau :

https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option "1" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
0
BigManUtd
 
j'ai déjà fait le truc avec Toolbar-S&D tout au début
0
loloetseb Messages postés 5684 Statut Membre 174
 
Postes moi le rapport a remover .J'ai fait une erreur de psote pour toolbar sd n'en tient pas compte (tu l'as deja fait).
0
loloetseb Messages postés 5684 Statut Membre 174
 
J'attends le rapport Ad remover,puis ensuite

Telecharges NAVILOG

Clique sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Clique sur navilog1.exe pour télécharger navilog1
Choisis Enregistrer

et enregistre-le sur ton bureau.

/ !\ Déconnecte-toi et désactive ton antivirus et antispyware résident pour que Navilog1 puisse s'exécuter normalement. /!\

Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Laisse-toi guider. Au menu principal, choisis 1 et valide.

Patiente jusqu'au message :
*** Analyse Terminée le ..... ***
Appuie sur une touche comme demandé, le bloc note va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le bloc note.
Le rapport est en outre sauvegardé à la racine du disque (C:\fixnavi.txt)
poste le rapport obtenu
0
BigManUtd
 
j'ai déjà posté le rapport de Ad-Remover
------- LOGFILE OF AD-REMOVER 1.1.0.9 | ONLY XP/VISTA -------

Updated by C_XX on 07/02/2009 at 14:30

Start at: 15:33:43 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 48

+--------------------| Boonty/Boonty Games Elements Found:

.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt

+--------------------| Eorezo Elements Found:

.

+--------------------| Infected Poker Softwares Elements Found:

HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Par­tyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\Everest Poker\data
C:\Program Files\Everest Poker\history
C:\Program Files\Everest Poker\data\fonts
C:\Program Files\Everest Poker\data\mp-lobby
C:\Program Files\Everest Poker\data\mp-poker
C:\Program Files\Everest Poker\data\shared
C:\Program Files\Everest Poker\data\startup
C:\Program Files\Everest Poker\data\mp-poker\background
C:\Program Files\Everest Poker\data\mp-poker\fr
C:\Program Files\Everest Poker\data\shared\fr
C:\Program Files\Everest Poker\data\shared\shared
C:\Program Files\Everest Poker\data\shared\shared\bitmaps
C:\Program Files\Everest Poker\data\shared\shared\sounds
C:\Program Files\Everest Poker\data\startup\en
C:\Program Files\Everest Poker\data\startup\fr
C:\Program Files\Everest Poker\data\startup\shared
C:\Program Files\Everest Poker\data\startup\shared\bitmaps
C:\Program Files\Everest Poker\data\startup\shared\icons
C:\Program Files\Everest Poker\data\startup\shared\sounds
C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\images
C:\Program Files\PartyGaming\Language
C:\Program Files\PartyGaming\PartyCasino
C:\Program Files\PartyGaming\PartyPoker
C:\Program Files\PartyGaming\tmpUpgrade
C:\Program Files\PartyGaming\Language\en_US
C:\Program Files\PartyGaming\Language\fr_FR
C:\Program Files\PartyGaming\Language\en_US\temp
C:\Program Files\PartyGaming\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyCasino\Images
C:\Program Files\PartyGaming\PartyCasino\Language
C:\Program Files\PartyGaming\PartyCasino\Temp
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE
C:\Program Files\PartyGaming\PartyCasino\Language\en_US
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE\images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\articles
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\lobby
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\ca­rdgames
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\ca­rdgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\ca­rdgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\ca­rdgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\ca­rdgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\ca­rdgames
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\ca­rdgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\ca­rdgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\ca­rdgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\ca­rdgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyPoker\Images
C:\Program Files\PartyGaming\PartyPoker\Language
C:\Program Files\PartyGaming\PartyPoker\NewSounds
C:\Program Files\PartyGaming\PartyPoker\PokerTrainer
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade
C:\Program Files\PartyGaming\PartyPoker\Images\NewGameTable
C:\Program Files\PartyGaming\PartyPoker\Language\en_US
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images\NewGameTa­ble
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt

+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Found:

.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d­4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3d­c201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9f­f05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt

+--------------------| It's TV Elements Found:

.

+--------------------| Sweetim Elements Found:

HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB1­7F182}
.

+--------------------| Added Scan:

---- Mozilla FireFox Version 3.0.6 ----

ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.

---- Internet Explorer Version 6.0.2900.2180 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr

+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]

SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.google.com
Start page: hxxp:/www.msn.com

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp:/ieframe.dll

+---------------------------------------------------------------------------+

[~7360 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-

End at: 15:37:01 | 08/02/2009
.
+--------------------| E.O.F - 142 Lines

ce que je n'arrive pas à faire, c'est ça:
Relances ad remover,fais A,puis cliques sur 1,3,4,6 puis S et postes moi le rapport.
moi je tape A, puis enter, puis le programme commence à analyser le systeme
je sais pas comment je dois faire pour cliquer 1,3,4,6 et S

puis quand j'instalerai NAVILOG, je dois désactiver mon anti-virus, c'est à dire mon avast:
pour le désactiver, je clique sur ' arreter la protection résidente' ?
0
loloetseb Messages postés 5684 Statut Membre 174
 
Ben au lieu de taper A tu tapes B et ensuite tu pourras faire 1,3,4,6 et S .Fais Ad remover avant de faire navilog
0
loloetseb Messages postés 5684 Statut Membre 174
 
Une fois que tu as fait ad remover et que tu m'as poster le rapport,tu fais navilog (tu desactives ton antivirus,cliques droit sur l'icone avast et ensuite desactiver la protection residente,puis tu fermes tous tes programmes y compris ta page web,le temps de faire navilog)
0
BigManUtd
 
------- LOGFILE OF AD-REMOVER 1.1.0.9 | ONLY XP/VISTA -------

Updated by C_XX on 07/02/2009 at 14:30

*** LIMITED TO ***

Boonty/BoontyGames
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
Sweetim

******************

Start at: 16:50:25 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 49

(!) ---- IE start pages/Tabs reset

+--------------------| Boonty/Boonty Games Elements Deleted :

.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt

+--------------------| Infected Poker Softwares Elements Deleted :

HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\PartyGaming
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt

+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :

.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt

+--------------------| Sweetim Elements Deleted :

HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
.

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.

+--------------------| Added Scan :

---- Mozilla FireFox Version 3.0.6 ----

ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.

---- Internet Explorer Version 6.0.2900.2180 ----

+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/go.microsoft.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.microsoft.com

+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]

Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/go.microsoft.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.microsoft.com

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
Search bar: hxxp:/search.msn.com
Search Page: hxxp:/www.microsoft.com
Start page: hxxp:/fr.msn.com

+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp:/ieframe.dll

+---------------------------------------------------------------------------+

[~3628 Bytes] - "C:\Ad-Report-Clean-08.02.2009.log"
[~7496 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-

End at: 17:01:04 | 08/02/2009
.
+--------------------| E.O.F - 84 Lines
.
0