Aidez moi à me débarrasser des pub CDI etc

Fermé
kendevalmont - 14 févr. 2009 à 18:01
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 - 15 févr. 2009 à 10:52
Bonjour,
je dois l'avouer je n'y connais rien en informatique.On m'a dit qu'ici je pourrais trouver des experts.Voici mon problème : je suis constament harcelé par des pub intempestive genre CDI,Casino etc et naturellement je vudrais m'en débarrasser.J'ai lu sur ce même formum que pour que vous m'aidiez vous avez besoin du "compte rendu" de mon ordinateur alors le voici : Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:50:31, on 14/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\runservice.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60201
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60201
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60201
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL
O2 - BHO: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Pure Global Each Help] C:\Documents and Settings\All Users\Application Data\META VIEW PURE GLOBAL\ExitCurb.exe
O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [morewin] C:\DOCUME~1\dimitri\APPLIC~1\GRAMVI~1\mpeg heck.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
O16 - DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} (WebLauncher Control) - http://www.aceonline.co.kr/game/WebLauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab55668.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game05.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Service Google Update (gupdate1c98dc9d5398c92) (gupdate1c98dc9d5398c92) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
A voir également:

6 réponses

funfy!!! Messages postés 66 Date d'inscription jeudi 12 février 2009 Statut Membre Dernière intervention 31 mars 2010 18
14 févr. 2009 à 18:04
Il y a un programme " Bloquer PUB intempestives ", Il y a écrit en haut de ta page " Autoriser les fenêtres Pop-up", il faut cliquer dessus.
3
toptitbal Messages postés 25709 Date d'inscription samedi 8 juillet 2006 Statut Contributeur sécurité Dernière intervention 4 mars 2010 2 230
14 févr. 2009 à 18:11
Bonjour

ça ne changera rien, l'ordinateur sera toujours infecté....
0
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
14 févr. 2009 à 18:03
Bonjour

Je regarde ton log et je repasse
0
funfy!!! Messages postés 66 Date d'inscription jeudi 12 février 2009 Statut Membre Dernière intervention 31 mars 2010 18
14 févr. 2009 à 18:13
Nettoie-le.
0
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
14 févr. 2009 à 18:13
Re



Fais ce qui suit dans l'ordre

1) -

C - Ccleaner :
(nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc.)
* Télécharge CCleaner.
(attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).

https://www.pcastuces.com/logitheque/ccleaner.htm
http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
Installe le dans un répertoire dédié.
Décoche pendant l'installation
--- les deux cases "Ajouter l'option ... "
--- Contrôler les mises à jour
* Lance Ccleaner pour un nettoyage complet.
Tutorial ici:
https://kerio.probb.fr/t242-tuto-ccleaner-v-2
https://www.malekal.com/tutoriel-ccleaner/
ET
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

======================================

2) -

Télécharge Lop S&D.exe sur ton bureau
tu télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

https://sites.google.com/site/dcangeldark/changelog
• Double-clique dessus pour lancer l'installation
• Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
• Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
• Patiente jusqu'à la fin du scan
• Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

========================================

3) -

Télécharge SmitfraudFix
Utilitaire de S!Ri: Moe et balltrap34
http://siri.urz.free.fr/Fix/SmitfraudFix.php

http://www.malekal.com/tutorial_SmitFraudfix.php
et télécharge SmitfraudFix.exe.

Regarde le tuto

Exécute le en choisissant l’option 1,
il va générer un rapport
Copie/colle le sur le poste stp.



@++


0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : dimitri ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:71 Go (Free:10 Go)
D:\ (Local Disk) - FAT32 - Total:71 Go (Free:71 Go)
E:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 14/02/2009|18:30 )

--------------------\\ Listing des dossiers dans APPLIC~1

[28/09/2006|08:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[28/09/2006|08:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[28/09/2006|08:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[22/02/2008|22:16] C:\DOCUME~1\alex\APPLIC~1\Adobe
[22/07/2007|21:08] C:\DOCUME~1\alex\APPLIC~1\AdobeUM
[02/01/2008|14:00] C:\DOCUME~1\alex\APPLIC~1\Apple Computer
[24/09/2007|17:52] C:\DOCUME~1\alex\APPLIC~1\ArcSoft
[31/03/2008|12:56] C:\DOCUME~1\alex\APPLIC~1\Creative
[21/10/2007|09:09] C:\DOCUME~1\alex\APPLIC~1\CyberLink
[03/05/2008|11:40] C:\DOCUME~1\alex\APPLIC~1\D-Jix Media
[09/02/2008|14:04] C:\DOCUME~1\alex\APPLIC~1\EPSON
[21/07/2007|15:53] C:\DOCUME~1\alex\APPLIC~1\Google
[23/05/2008|21:45] C:\DOCUME~1\alex\APPLIC~1\Identities
[30/12/2008|16:21] C:\DOCUME~1\alex\APPLIC~1\InstallShield
[30/12/2008|17:17] C:\DOCUME~1\alex\APPLIC~1\LGSync
[28/09/2006|08:45] C:\DOCUME~1\alex\APPLIC~1\Macromedia
[03/05/2008|11:34] C:\DOCUME~1\alex\APPLIC~1\Microsoft
[20/08/2007|11:27] C:\DOCUME~1\alex\APPLIC~1\Motive
[27/07/2007|09:55] C:\DOCUME~1\alex\APPLIC~1\MySpace
[24/05/2008|06:27] C:\DOCUME~1\alex\APPLIC~1\PlayFirst
[18/07/2008|21:13] C:\DOCUME~1\alex\APPLIC~1\Real
[09/10/2007|14:01] C:\DOCUME~1\alex\APPLIC~1\Samsung
[24/05/2008|06:25] C:\DOCUME~1\alex\APPLIC~1\Sun
[19/01/2008|19:01] C:\DOCUME~1\alex\APPLIC~1\Symantec
[23/05/2008|21:45] C:\DOCUME~1\alex\APPLIC~1\Zylom

[30/12/2008|15:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[14/01/2009|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[10/09/2007|23:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[10/09/2007|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[22/08/2007|17:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[26/06/2008|11:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[11/12/2008|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BSD
[11/12/2008|16:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BSD Concept
[31/03/2008|13:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[31/12/2006|17:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[14/02/2009|16:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
[22/12/2008|11:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/02/2009|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
[26/11/2007|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[25/03/2007|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[21/07/2007|15:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\META VIEW PURE GLOBAL
[28/03/2008|13:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[31/12/2006|16:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[13/01/2007|16:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MotiveSysIDs
[27/12/2006|13:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Newsoft
[17/01/2009|20:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton
[17/01/2009|20:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[10/02/2007|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[17/01/2009|20:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PCSettings
[06/03/2007|14:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
[27/01/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PrettyGoodGames
[16/01/2007|13:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[14/01/2009|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[08/09/2008|15:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
[17/01/2009|20:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[27/06/2008|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/02/2008|22:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[29/12/2006|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[17/01/2007|18:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[18/01/2007|09:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[17/07/2007|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
[13/03/2008|18:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[29/12/2006|14:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[05/08/2008|20:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[21/10/2008|17:13] C:\DOCUME~1\corinne\APPLIC~1\Adobe
[06/12/2008|19:53] C:\DOCUME~1\corinne\APPLIC~1\EoRezo
[18/01/2007|10:11] C:\DOCUME~1\corinne\APPLIC~1\Google
[28/09/2006|08:45] C:\DOCUME~1\corinne\APPLIC~1\Identities
[28/09/2006|08:45] C:\DOCUME~1\corinne\APPLIC~1\Macromedia
[18/01/2007|10:09] C:\DOCUME~1\corinne\APPLIC~1\Microsoft
[28/10/2008|16:18] C:\DOCUME~1\corinne\APPLIC~1\OpenOffice.org
[17/08/2008|13:18] C:\DOCUME~1\corinne\APPLIC~1\Real
[28/09/2008|12:00] C:\DOCUME~1\corinne\APPLIC~1\Sun
[27/01/2008|18:00] C:\DOCUME~1\corinne\APPLIC~1\Symantec

[26/12/2007|18:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Apple Computer
[28/09/2006|08:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[28/09/2006|08:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[28/09/2006|08:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[18/10/2008|19:12] C:\DOCUME~1\dimitri\APPLIC~1\Adobe
[11/05/2008|21:28] C:\DOCUME~1\dimitri\APPLIC~1\AdobeUM
[10/09/2007|23:14] C:\DOCUME~1\dimitri\APPLIC~1\Apple Computer
[22/09/2007|16:07] C:\DOCUME~1\dimitri\APPLIC~1\ArcSoft
[22/08/2007|17:21] C:\DOCUME~1\dimitri\APPLIC~1\Babylon
[11/12/2008|16:54] C:\DOCUME~1\dimitri\APPLIC~1\BSD Concept
[22/08/2007|22:07] C:\DOCUME~1\dimitri\APPLIC~1\Camfrog
[24/04/2008|21:15] C:\DOCUME~1\dimitri\APPLIC~1\Creative
[17/01/2009|23:19] C:\DOCUME~1\dimitri\APPLIC~1\DivX
[13/08/2007|00:27] C:\DOCUME~1\dimitri\APPLIC~1\eMule
[07/12/2008|16:39] C:\DOCUME~1\dimitri\APPLIC~1\EoRezo
[29/12/2006|14:46] C:\DOCUME~1\dimitri\APPLIC~1\EPSON
[24/02/2007|18:25] C:\DOCUME~1\dimitri\APPLIC~1\FUJIFILM
[14/01/2007|13:35] C:\DOCUME~1\dimitri\APPLIC~1\Google
[25/12/2007|20:57] C:\DOCUME~1\dimitri\APPLIC~1\GrabIt
[28/06/2007|20:00] C:\DOCUME~1\dimitri\APPLIC~1\Gram View 4
[29/04/2008|17:50] C:\DOCUME~1\dimitri\APPLIC~1\Help
[28/09/2006|08:45] C:\DOCUME~1\dimitri\APPLIC~1\Identities
[08/10/2007|20:17] C:\DOCUME~1\dimitri\APPLIC~1\InstallShield
[14/03/2007|17:36] C:\DOCUME~1\dimitri\APPLIC~1\Lavasoft
[01/05/2008|19:40] C:\DOCUME~1\dimitri\APPLIC~1\LGSync
[05/02/2009|20:25] C:\DOCUME~1\dimitri\APPLIC~1\LimeWire
[06/03/2007|14:28] C:\DOCUME~1\dimitri\APPLIC~1\Logitech
[02/01/2008|10:01] C:\DOCUME~1\dimitri\APPLIC~1\Macromedia
[27/01/2009|19:34] C:\DOCUME~1\dimitri\APPLIC~1\Microsoft
[13/01/2007|21:25] C:\DOCUME~1\dimitri\APPLIC~1\Motive
[07/07/2007|16:26] C:\DOCUME~1\dimitri\APPLIC~1\Mozilla
[13/01/2007|21:33] C:\DOCUME~1\dimitri\APPLIC~1\MSNInstaller
[26/07/2007|16:34] C:\DOCUME~1\dimitri\APPLIC~1\MySpace
[30/10/2008|21:29] C:\DOCUME~1\dimitri\APPLIC~1\OpenOffice.org
[11/06/2008|00:09] C:\DOCUME~1\dimitri\APPLIC~1\Real
[24/03/2007|15:19] C:\DOCUME~1\dimitri\APPLIC~1\Screenshot Sender
[07/07/2007|16:27] C:\DOCUME~1\dimitri\APPLIC~1\SecondLife
[14/01/2007|13:41] C:\DOCUME~1\dimitri\APPLIC~1\Sun
[19/01/2008|18:42] C:\DOCUME~1\dimitri\APPLIC~1\Symantec
[04/03/2007|14:05] C:\DOCUME~1\dimitri\APPLIC~1\U3
[21/03/2007|15:51] C:\DOCUME~1\dimitri\APPLIC~1\XnView


[20/01/2007|12:02] C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
[20/01/2007|12:02] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[28/09/2006|08:45] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[14/01/2009|09:44] C:\DOCUME~1\papa\APPLIC~1\Adobe
[29/05/2008|15:38] C:\DOCUME~1\papa\APPLIC~1\AdobeUM
[14/02/2008|16:41] C:\DOCUME~1\papa\APPLIC~1\Apple Computer
[01/02/2009|18:26] C:\DOCUME~1\papa\APPLIC~1\Creative
[01/01/2009|15:20] C:\DOCUME~1\papa\APPLIC~1\DivX
[07/12/2008|20:57] C:\DOCUME~1\papa\APPLIC~1\EoRezo
[03/01/2007|10:38] C:\DOCUME~1\papa\APPLIC~1\EPSON
[16/01/2007|13:46] C:\DOCUME~1\papa\APPLIC~1\FUJIFILM
[16/01/2007|16:22] C:\DOCUME~1\papa\APPLIC~1\Google
[28/09/2006|08:45] C:\DOCUME~1\papa\APPLIC~1\Identities
[15/03/2007|15:03] C:\DOCUME~1\papa\APPLIC~1\Lavasoft
[14/01/2009|10:15] C:\DOCUME~1\papa\APPLIC~1\Leadertech
[06/03/2007|11:02] C:\DOCUME~1\papa\APPLIC~1\Logitech
[28/09/2006|08:45] C:\DOCUME~1\papa\APPLIC~1\Macromedia
[22/12/2008|16:48] C:\DOCUME~1\papa\APPLIC~1\Microsoft
[05/03/2007|14:15] C:\DOCUME~1\papa\APPLIC~1\Motive
[27/07/2007|09:32] C:\DOCUME~1\papa\APPLIC~1\MySpace
[30/10/2008|10:07] C:\DOCUME~1\papa\APPLIC~1\OpenOffice.org
[21/07/2008|13:15] C:\DOCUME~1\papa\APPLIC~1\Real
[01/05/2008|20:57] C:\DOCUME~1\papa\APPLIC~1\Samsung
[11/10/2007|08:00] C:\DOCUME~1\papa\APPLIC~1\SecondLife
[08/02/2007|13:41] C:\DOCUME~1\papa\APPLIC~1\Sun
[19/01/2008|17:46] C:\DOCUME~1\papa\APPLIC~1\Symantec
[10/12/2008|18:20] C:\DOCUME~1\papa\APPLIC~1\U3

[20/06/2008|12:12] C:\DOCUME~1\SEBAST~1\APPLIC~1\Adobe
[25/01/2007|15:53] C:\DOCUME~1\SEBAST~1\APPLIC~1\AdobeUM
[24/01/2007|14:41] C:\DOCUME~1\SEBAST~1\APPLIC~1\CyberLink
[18/01/2007|09:24] C:\DOCUME~1\SEBAST~1\APPLIC~1\FUJIFILM
[26/01/2007|08:44] C:\DOCUME~1\SEBAST~1\APPLIC~1\Google
[28/09/2006|08:45] C:\DOCUME~1\SEBAST~1\APPLIC~1\Identities
[27/06/2008|12:50] C:\DOCUME~1\SEBAST~1\APPLIC~1\Macromedia
[14/02/2007|17:40] C:\DOCUME~1\SEBAST~1\APPLIC~1\Microsoft
[13/01/2007|18:07] C:\DOCUME~1\SEBAST~1\APPLIC~1\Motive
[13/01/2007|18:24] C:\DOCUME~1\SEBAST~1\APPLIC~1\MSNInstaller
[20/06/2008|12:07] C:\DOCUME~1\SEBAST~1\APPLIC~1\Real
[26/01/2007|08:46] C:\DOCUME~1\SEBAST~1\APPLIC~1\Sun
[24/01/2008|22:01] C:\DOCUME~1\SEBAST~1\APPLIC~1\Symantec


--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[14/02/2009 17:40][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[14/02/2009 17:41][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[10/02/2009 15:43][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[14/02/2009 18:00][--ah-----] C:\WINDOWS\tasks\AED4E4BB919B627B.job
[14/02/2009 17:42][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[14/02/2009 17:40][--ah-----] C:\WINDOWS\tasks\SA.DAT
[10/08/2004 21:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

( AED4E4BB919B627B.job )=( c:\docume~1\dimitri\applic~1\gramvi~1\meetonegrim.exe )

--------------------\\ Listing des dossiers dans C:\Program Files

[30/12/2006|15:49] C:\Program Files\ABBYY FineReader 6.0 Sprint
[28/09/2006|08:46] C:\Program Files\Acer WLAN 11g USB Dongle
[14/01/2009|09:44] C:\Program Files\Adobe
[28/08/2007|22:26] C:\Program Files\Adverts
[23/09/2007|15:11] C:\Program Files\AnglaisFacile.com
[23/03/2007|19:31] C:\Program Files\AnmSMP
[28/04/2008|15:48] C:\Program Files\Anuman Interactive
[30/12/2008|14:55] C:\Program Files\Apple Software Update
[16/01/2007|13:43] C:\Program Files\ArcSoft
[26/08/2008|11:19] C:\Program Files\ARUSH Entertainment
[26/08/2008|11:31] C:\Program Files\Atari
[31/03/2008|13:41] C:\Program Files\Audible
[25/02/2008|14:14] C:\Program Files\BoltSoft
[30/12/2008|14:57] C:\Program Files\Bonjour
[26/06/2008|11:41] C:\Program Files\Boonty
[26/06/2008|14:02] C:\Program Files\BoontyGames
[18/07/2008|18:50] C:\Program Files\BroadJump
[10/11/2008|19:50] C:\Program Files\Brodaroda
[11/12/2008|16:54] C:\Program Files\BSD Concept
[10/12/2008|10:44] C:\Program Files\Camfrog
[14/02/2009|18:20] C:\Program Files\CCleaner
[18/07/2008|19:07] C:\Program Files\Club-Internet
[28/09/2006|08:46] C:\Program Files\commercial
[10/11/2008|19:38] C:\Program Files\Common Files
[11/08/2006|18:27] C:\Program Files\ComPlus Applications
[14/02/2009|18:29] C:\Program Files\Crawler
[31/03/2008|13:33] C:\Program Files\Creative
[31/03/2008|13:39] C:\Program Files\Creative Installation Information
[28/09/2006|08:46] C:\Program Files\CyberLink
[26/08/2008|10:13] C:\Program Files\Deer Drive
[28/09/2006|08:46] C:\Program Files\DIFX
[05/03/2008|15:07] C:\Program Files\Disney
[30/12/2008|16:32] C:\Program Files\DivX
[03/05/2008|11:33] C:\Program Files\D-Jix
[06/12/2007|17:03] C:\Program Files\EA SPORTS
[28/12/2008|11:39] C:\Program Files\eMule
[07/12/2008|16:39] C:\Program Files\EoRezo
[06/12/2007|17:01] C:\Program Files\epson
[17/01/2009|20:08] C:\Program Files\Fichiers communs
[16/01/2007|13:36] C:\Program Files\FinePixViewer
[11/02/2008|17:23] C:\Program Files\FlightGear
[05/02/2008|15:53] C:\Program Files\FMS
[28/09/2006|08:46] C:\Program Files\FrenchOtto
[27/01/2008|21:28] C:\Program Files\Gamenext
[27/01/2008|21:28] C:\Program Files\GamesBar
[26/08/2008|11:57] C:\Program Files\GameSpy Arcade
[28/09/2006|08:46] C:\Program Files\GemMasterFrench
[13/02/2009|11:59] C:\Program Files\Google
[26/03/2008|15:53] C:\Program Files\Gpotato
[24/03/2007|15:19] C:\Program Files\Gram View 4
[10/11/2008|19:39] C:\Program Files\InstallShield Installation Information
[10/12/2008|22:27] C:\Program Files\Internet Explorer
[30/12/2008|15:05] C:\Program Files\iPod
[30/12/2008|15:05] C:\Program Files\iTunes
[07/09/2008|11:04] C:\Program Files\Java
[20/10/2008|18:42] C:\Program Files\JRE
[13/03/2007|17:11] C:\Program Files\Lavasoft
[10/11/2008|19:43] C:\Program Files\Legacy Interactive
[05/03/2008|14:37] C:\Program Files\Les Catacombes d'Uranium
[07/06/2008|19:15] C:\Program Files\LG Electronics
[03/11/2008|19:40] C:\Program Files\LG PC Suite 2
[01/05/2008|09:37] C:\Program Files\LGE GSM PC Sync
[13/03/2008|19:27] C:\Program Files\LimeWire
[06/03/2007|10:58] C:\Program Files\Logitech
[03/03/2008|15:51] C:\Program Files\MAIET
[14/08/2008|07:22] C:\Program Files\Messenger
[25/10/2008|19:00] C:\Program Files\Messenger Plus! Live
[09/05/2007|13:14] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[28/09/2006|08:46] C:\Program Files\microsoft frontpage
[28/03/2008|12:55] C:\Program Files\Microsoft Games
[18/07/2008|18:52] C:\Program Files\Motive
[28/09/2006|08:46] C:\Program Files\Movie Maker
[28/12/2006|12:09] C:\Program Files\MP3 Player Utilities
[14/11/2008|15:27] C:\Program Files\MSECache
[30/12/2006|10:04] C:\Program Files\MSN
[09/06/2007|14:03] C:\Program Files\MSN Games
[28/09/2006|08:46] C:\Program Files\MSN Gaming Zone
[28/08/2007|22:26] C:\Program Files\MSN Messenger
[08/03/2007|07:56] C:\Program Files\MSXML 4.0
[27/08/2007|12:44] C:\Program Files\MSXML 6.0
[28/07/2007|22:35] C:\Program Files\MySpace
[30/12/2008|18:34] C:\Program Files\NAVIGON
[14/02/2009|15:07] C:\Program Files\Navilog1
[28/09/2006|08:46] C:\Program Files\NetMeeting
[27/12/2006|14:03] C:\Program Files\NewSoft
[28/09/2006|08:46] C:\Program Files\NewTech Infosystems
[17/01/2009|20:16] C:\Program Files\Norton Internet Security
[16/01/2008|00:44] C:\Program Files\Norton Security Scan
[18/01/2009|09:28] C:\Program Files\NortonInstaller
[09/04/2008|19:51] C:\Program Files\NRJ
[28/09/2006|08:47] C:\Program Files\Oca History Tool
[28/09/2006|08:47] C:\Program Files\Online Services
[20/10/2008|18:42] C:\Program Files\OpenOffice.org 3
[14/06/2007|11:41] C:\Program Files\Outlook Express
[22/09/2007|13:51] C:\Program Files\Philips
[24/03/2008|22:15] C:\Program Files\PhotoFiltre
[16/10/2008|20:58] C:\Program Files\PopCap Games
[16/01/2009|13:43] C:\Program Files\Pvm
[30/12/2008|14:57] C:\Program Files\QuickTime
[22/10/2008|20:25] C:\Program Files\Radio Fr Solo
[12/02/2008|13:59] C:\Program Files\Razorworks
[25/01/2007|16:56] C:\Program Files\Real
[28/09/2006|08:47] C:\Program Files\Realtek
[26/08/2007|19:44] C:\Program Files\Reference Assemblies
[16/01/2007|13:33] C:\Program Files\REGSHAVE
[19/11/2007|16:36] C:\Program Files\RomuSoft
[09/10/2007|13:46] C:\Program Files\Samsung
[15/01/2009|22:10] C:\Program Files\Seagrand
[28/09/2006|08:47] C:\Program Files\Services en ligne
[05/02/2008|17:00] C:\Program Files\Sierra
[27/02/2008|12:27] C:\Program Files\Simulateur de conduite 3D Demo
[12/02/2008|13:27] C:\Program Files\Softnyx
[25/02/2008|16:25] C:\Program Files\Strategy First
[08/09/2008|15:34] C:\Program Files\SweetIM
[17/01/2009|20:17] C:\Program Files\Symantec
[26/06/2008|11:49] C:\Program Files\T‚l‚chargeur de Architecte 3D Silver 2007
[28/04/2008|16:01] C:\Program Files\The Learning Company
[11/09/2007|18:54] C:\Program Files\The Weather Channel FW
[14/02/2009|17:49] C:\Program Files\Trend Micro
[30/03/2008|15:27] C:\Program Files\Trymedia
[26/03/2008|17:43] C:\Program Files\Ultimate Duck Hunting
[11/08/2006|18:40] C:\Program Files\Uninstall Information
[10/03/2008|15:23] C:\Program Files\VID_0E8F&PID_1006
[19/04/2008|08:23] C:\Program Files\VideoLAN
[17/07/2007|12:55] C:\Program Files\Windows Live
[30/11/2007|10:05] C:\Program Files\Windows Live Favorites
[30/11/2007|10:06] C:\Program Files\Windows Live Toolbar
[01/02/2007|17:25] C:\Program Files\Windows Media Connect 2
[01/02/2007|17:25] C:\Program Files\Windows Media Player
[28/09/2006|08:47] C:\Program Files\Windows NT
[28/09/2006|08:47] C:\Program Files\Windows Plus
[17/01/2009|20:15] C:\Program Files\Windows Sidebar
[11/08/2006|18:28] C:\Program Files\WindowsUpdate
[23/04/2008|17:59] C:\Program Files\World of Pirates
[28/09/2006|08:47] C:\Program Files\xerox
[14/02/2007|18:01] C:\Program Files\Xvid
[27/09/2007|13:19] C:\Program Files\Yahoo!
[23/05/2008|21:47] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[14/01/2009|09:42] C:\Program Files\Fichiers communs\Adobe
[30/12/2008|15:05] C:\Program Files\Fichiers communs\Apple
[22/09/2007|13:52] C:\Program Files\Fichiers communs\ArcSoft
[21/12/2007|17:47] C:\Program Files\Fichiers communs\Blizzard Entertainment
[26/06/2008|11:42] C:\Program Files\Fichiers communs\BOONTY Shared
[31/03/2008|12:28] C:\Program Files\Fichiers communs\Creative
[27/12/2006|13:50] C:\Program Files\Fichiers communs\Digi338
[27/12/2006|13:35] C:\Program Files\Fichiers communs\InstallShield
[27/12/2006|13:01] C:\Program Files\Fichiers communs\Java
[28/09/2006|08:46] C:\Program Files\Fichiers communs\LightScribe
[26/11/2007|22:56] C:\Program Files\Fichiers communs\Logitech
[14/11/2008|17:45] C:\Program Files\Fichiers communs\Microsoft Shared
[31/12/2006|15:36] C:\Program Files\Fichiers communs\Motive
[16/09/2007|17:05] C:\Program Files\Fichiers communs\Motorola Shared
[28/09/2006|08:46] C:\Program Files\Fichiers communs\MSSoap
[28/09/2006|08:46] C:\Program Files\Fichiers communs\muvee Technologies
[29/12/2006|13:28] C:\Program Files\Fichiers communs\NewSoft
[28/09/2006|08:46] C:\Program Files\Fichiers communs\NewTech Infosystems
[27/01/2008|21:28] C:\Program Files\Fichiers communs\Oberon Media
[28/09/2006|08:46] C:\Program Files\Fichiers communs\ODBC
[11/06/2008|00:05] C:\Program Files\Fichiers communs\Real
[28/09/2006|08:46] C:\Program Files\Fichiers communs\Services
[10/09/2007|13:26] C:\Program Files\Fichiers communs\snpstd
[22/09/2007|13:51] C:\Program Files\Fichiers communs\SPC500NC
[28/09/2006|08:46] C:\Program Files\Fichiers communs\SpeechEngines
[17/01/2009|20:17] C:\Program Files\Fichiers communs\Symantec Shared
[14/06/2007|11:41] C:\Program Files\Fichiers communs\System
[26/12/2007|19:14] C:\Program Files\Fichiers communs\Vbox
[11/01/2008|19:44] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[11/06/2008|00:05] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 58 Processes )

iexplore.exe ~ [PID:848]
iexplore.exe ~ [PID:1984]

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\dimitri\APPLIC~1\Gram View 4
C:\DOCUME~1\dimitri\APPLIC~1\Gram View 4\nlgqxasm.exe
C:\DOCUME~1\dimitri\APPLIC~1\Gram View 4\uploadsettingsfacehole.exe
C:\Program Files\Gram View 4
C:\DOCUME~1\dimitri\APPLIC~1\gramvi~1
C:\DOCUME~1\dimitri\APPLIC~1\gramvi~1\nlgqxasm.exe
C:\DOCUME~1\dimitri\APPLIC~1\gramvi~1\uploadsettingsfacehole.exe
C:\Program Files\gramvi~1
C:\Program Files\Adverts
C:\WINDOWS\Tasks\AED4E4BB919B627B.job

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"morewin"="C:\\DOCUME~1\\dimitri\\APPLIC~1\\GRAMVI~1\\mpeg heck.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 18:31:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 438

--------------------\\ Recherche d'autres infections

--------------------\\ Suspect ..

C:\WINDOWS\myalbum2007.zip


Aucune autre infection trouvée !

[F:41][D:1]-> C:\DOCUME~1\dimitri\LOCALS~1\Temp
[F:1][D:0]-> C:\DOCUME~1\dimitri\Cookies
[F:4][D:2]-> C:\DOCUME~1\dimitri\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 14/02/2009|18:36 - Option : [1]

--------------------\\ Fin du rapport a 18:36:58


voila le premier rapport que tu m'a demandé.
0
voici le second.merci de l'interet que tu porte à mon problème.


SmitFraudFix v2.395

Rapport fait à 18:42:38,48, 14/02/2009
Executé à partir de C:\Documents and Settings\dimitri\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\runservice.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\dimitri\Bureau\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

Fichier hosts corrompu !

127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\dimitri


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\dimitri\LOCALS~1\Temp


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\dimitri\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\dimitri\Favoris


»»»»»»»»»»»»»»»»»»»»»»»» Bureau


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"


»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» RK



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Generic Marvell Yukon Chipset based Ethernet Controller - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{6D518433-D9E1-45A0-80D4-BAA85289F3DE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{6D518433-D9E1-45A0-80D4-BAA85289F3DE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{6D518433-D9E1-45A0-80D4-BAA85289F3DE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
15 févr. 2009 à 10:52
Bonjour

1) -

Relance Lop S&D
• Choisis cette fois ci l'Option 2 ( Suppression )
• Ne ferme pas la fenêtre lors de la suppression !
• Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )


==========================================

2) -

Télécharge HostsXpert sur ton Bureau :
http://www.funkytoad.com/download/HostsXpert.zip

---> Décompresse-le (Clic droit >> Extraire ici)

---> Double-clique sur HostsXpert pour le lancer

---> clique sur le bouton "Restore MS Hosts File" puis ferme le programme

PS : Avant de cliquer sur le bouton "Restore MS Hosts File", vérifie que le cadenas en haut à gauche est ouvert sinon tu vas avoir un message d'erreur.

==========================================

3) -

Nettoyage :
Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).

http://www.coupdepoucepc.com/modules/news/article.php?storyid=253
https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

----------------------------------------------------------------------------
Relance le programme Smitfraud,
Cette fois choisit l’option 2, répond oui a tous ;
Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

process.exe
est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
http://www.beyondlogic.org/consulting/processutil/processutil.htm


===================================

4) -

+ un log Hijackthis en Mode Normal

@++
0