Ordinateur virusé!!

Fermé
ffull41 - 22 mai 2009 à 16:50
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 - 30 mai 2009 à 22:43
Bonjour,
Eh bien le titre parle tout seul! Mon ordinateur a était virusé, et je ne veux pas le formater, quelqu'un a une idée de ce que je dois faire s'il vous plait?

Détails supplémentaires: Je pense avoir été virusé par une amie. En effet, ce virus envoyait des messages sur msn à tout le monde, j'en ai ouvert un (ne sachant pas qu'elle était virusée), et maintenant me voila virusé!

45 réponses

Alors là, c'est le rapport qui a dans "moved files"

========== PROCESSES ==========
Process explorer.exe killed successfully.
Unable to kill process: EoEngine.exe
========== FILES ==========
c:\program files\eorezo\eoadv\EoRezoBHO.dll NOT unregistered.
File move failed. c:\program files\eorezo\eoadv\EoRezoBHO.dll scheduled to be moved on reboot.
File move failed. c:\program files\eorezo\EoEngine.exe scheduled to be moved on reboot.
c:\program files\netants\NaGet.htm moved successfully.
c:\program files\netants\NaGetAll.htm moved successfully.
File/Folder e:\adober.exe not found.
File/Folder f:\adober.exe not found.
File move failed. c:\windows\system32\rundll32.exe scheduled to be moved on reboot.
========== COMMANDS ==========
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\burnlib.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\dsp_sps.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_aacplus.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_flac.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_flake.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_lame.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_vorbis.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_wav.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\enc_wma.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_crasher.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_dropbox.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_ff.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_hotkeys.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_ml.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\gen_tray.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_cdda.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_dshow.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_flac.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_flv.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_linein.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_midi.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_mod.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_mp3.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_mp4.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_nsv.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_swf.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_vorbis.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_wave.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\in_wm.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_autotag.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_bookmarks.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_dash.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_disc.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_history.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_impex.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_local.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_nowplaying.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_online.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_orb.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_playlists.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_plg.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_pmp.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_rg.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_transcode.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\ml_wire.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\out_disk.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\out_ds.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\out_wave.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\playlist.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\pmp_activesync.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\pmp_ipod.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\pmp_njb.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\pmp_p4s.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\pmp_usb.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\tagz.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\vis_milk2.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\vis_nsfs.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\WLZEA5E.tmp\winamp.lng scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8837.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8845.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF88D4.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF88E7.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF894A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF895D.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8AB4.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8AEA.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8C48.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8C64.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8D8C.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8DAD.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8E0A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8E25.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8E93.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8EA1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8EFB.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~DF8F09.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Elise\AppData\Local\Temp\~ROMFN_00000894 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Windows Temp folder emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05312009_140057
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 14:25
Ok.

Va vérifier si tu trouves ceci:

c:\program files\eorezo\eoadv\eorezobho.dll
c:\program files\eorezo\eoengine.exe
c:\program files\netants\naget.htm
c:\program files\netants\nagetall.htm
e:\adober.exe
f:\adober.exe


si oui, tu vires.

Fais la suite si tu ne l'as pas encore faite.
0
voila le rapport de GenProc. Je dois faire ce qu'il dit (télécharger tout ces trucs)?

Rapport GenProc 2.572 [1]
@ 31/05/2009 à 14:23:44
@ Windows Vista Service Pack 1

# Etape 1/ Télécharge :

- CCleaner https://www.ccleaner.com/ccleaner/download (FileHippo). Ce logiciel va permettre de supprimer tous les fichiers temporaires. Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.


- rustbfix http://uploads.ejvindh.andymanchesta.com/RustbFix.exe ( (ejvindh) et sauvegarde-le sur ton Bureau.
- Double clique sur rustbfix.exe afin de lancer l'outil.
- Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer l'ordi.
- Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis. Tout cela se fera automatiquement.

- Suite au(x) redémarrage(s), deux rapports s'ouvriront : (C:\avenger.txt & C:\rustbfix\pelog.txt).
- Poste le contenu de ces deux rapports, ainsi qu'un rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm


----------------------------------------------------------------------

~~ Arguments de la procédure ~~


# Détections [1] GenProc 2.572 31/05/2009 à 14:23:44
Rustock: le 31/05/2009 à 14:23:44 "pe386" present
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 14:33
Suis la procédure indiquée.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
voila j'ai tout viré sauf: e:\...... et f:\..... car mon ordinateur dit qu'ils existent pas.
J'attaque les étape de genproc
0
ok pour la procédure, j'ai modifié les paramètres. Mais ils disent de fermer le programme, je dois meme pas tout nettoyer avant?
0
j'ai fait l'étape avec rustbfix avtn de nettoyer le disque avec ccleaner, il m'a donné ça:

************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
31/05/2009 14:44:51,64

No Rustock.b-rootkits found

******************************* End of Logfile ********************************
0
désolé, je n'ai pas attendu pour savoir si je devais tout nettoyer, j'ai pensé que que c'était logique après tout ^^. En tout je l'ai fait, et j'ai refait rusbfix et il m'a marqué la meme chose sur le bloc notes
0
j'ai une question: une fois tout ce travail fini, je pourrai supprimer tout les logiciels que j'ai téléchargé pour le dévirusé?
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 17:44
Et le rapport Hijackthis, tu ne l'as pas posté.

Oui, à la fin on supprimera les outils utilisés.
0
ffull41 Messages postés 2 Date d'inscription vendredi 22 mai 2009 Statut Membre Dernière intervention 30 mai 2009
30 mai 2009 à 17:51
rapport de hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:35, on 30/05/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Users\Elise\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Winamp\winamp.exe
c:\program files\winamp toolbar\WinampTbServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig?hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\Elise\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download by NetAnts - C:\PROGRA~1\NetAnts\NAGet.htm
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download &All by NetAnts - C:\PROGRA~1\NetAnts\NAGetAll.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9e13cdf6571d5) (gupdate1c9e13cdf6571d5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: L Ile Noyee Drivers Auto Removal (pr2ajbeb) (pr2ajbeb) - Micro Application - C:\Windows\system32\pr2ajbeb.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 18:08
Télécharge Ad-Remover :

http://sd-1.archive-host.com/membres/up/16506160323759868/AD¬-R.exe

/!\ Déconnectes toi et fermes toutes applications en cours

▶ Double clique sur "Ad-R.exe" pour lancer l'installation en laissant les paramètres d'installation par défaut .

Double clique sur l'icône Ad-remover situé sur ton bureau.

▶ Au menu principal choisi l'option "L" et appuie sur Entrée.

▶Postes le rapport qui apparait à la fin.

▶Le rapport est sauvegardé aussi sous C:\Ad-report.log

(CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
0
ffull41 Messages postés 2 Date d'inscription vendredi 22 mai 2009 Statut Membre Dernière intervention 30 mai 2009
30 mai 2009 à 18:11
pour ad-remove, mon ordi dit que le lien et corrompu, afin qu'il ne mène à rien :(
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 18:18
0
le logiciel dit que les comptes d'utilisateurs sont surveillés, et donc que je doit en parler au "helper" qui m'aide. Quand j'ai lançais le truc (donc une fois que j'ai entré "L"), ça m'a marqué plein de fois "accès refusé"
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 20:34
Ok.

/!\ si tu as Vista, désactive l’UAC le temps de la désinfection :
Panneau de configuration>comptes utilisateurs>activer/désactiver le contrôle des comptes utilisateurs>décoche la cas puis fais OK .
0
Voici le rapport:


------- RAPPORT D'AD-REMOVER 1.1.4.4 | UNIQUEMENT XP/VISTA -------

Mit à jour part C_XX le 28/05/2009 à 19:50
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

Lancé à: 20:56:57, 30/05/2009 | Mode Normal
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
Nom du PC: PC-DE-ELISE
Utilisateur actuel: Elise - Administrateur

.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
HKCR\AppID\EoRezoBHO.DLL
HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKCR\EoRezoBHO.EoBho
HKCR\EoRezoBHO.EoBho.1
HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
.
C:\Users\Elise\AppData\Roaming\EoRezo\cmhost.cyp
C:\Users\Elise\AppData\Roaming\EoRezo\ConfMedia.cyp
/!\ NON SUPPRIMÉ: C:\Users\Elise\AppData\Roaming\EoRezo\db
/!\ NON SUPPRIMÉ: C:\Users\Elise\AppData\Roaming\EoRezo\eoDesktop
C:\Users\Elise\AppData\Roaming\EoRezo\host.cyp
C:\Users\Elise\AppData\Roaming\EoRezo\modules.cyp
C:\Users\Elise\AppData\Roaming\EoRezo\user.cyp
C:\Users\Elise\AppData\Roaming\EoRezo\db\cat.cyp
C:\Users\Elise\AppData\Roaming\EoRezo\eoDesktop\config.xml
C:\Users\Elise\AppData\Roaming\EoRezo\eoDesktop\eoDesktop.html
C:\Users\Elise\AppData\Roaming\EoRezo\eoDesktop\userConfig.xml
C:\Users\Elise\AppData\Roaming\EoRezo
C:\Program Files\EoRezo\ConfMedia.cyp
/!\ NON SUPPRIMÉ: C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\eoEngine.url
C:\Program Files\EoRezo\EoMultiLanguage.dll
C:\Program Files\EoRezo\EoRezoComm.dll
C:\Program Files\EoRezo\EoRezoImg_17.dll
C:\Program Files\EoRezo\EoRezoImg_19.dll
C:\Program Files\EoRezo\EoRezoImg_20.dll
C:\Program Files\EoRezo\EoRezoImg_21.dll
C:\Program Files\EoRezo\EoRezoImg_22.dll
C:\Program Files\EoRezo\EoRezoImg_23.dll
C:\Program Files\EoRezo\EoRezoTools_16.dll
C:\Program Files\EoRezo\EoRezoTools_17.dll
C:\Program Files\EoRezo\EoRezoTools_18.dll
C:\Program Files\EoRezo\EoRezoTools_20.dll
C:\Program Files\EoRezo\EoRezoTools_21.dll
C:\Program Files\EoRezo\EoRezoTools_26.dll
C:\Program Files\EoRezo\EoRezoTools_27.dll
C:\Program Files\EoRezo\EoRezoTools_28.dll
C:\Program Files\EoRezo\FreeImage.dll
C:\Program Files\EoRezo\Host.cyp
/!\ NON SUPPRIMÉ: C:\Program Files\EoRezo\lang
C:\Program Files\EoRezo\MngInstaller.dll
C:\Program Files\EoRezo\unins000.dat
C:\Program Files\EoRezo\unins000.exe
C:\Program Files\EoRezo\user.cyp
C:\Program Files\EoRezo\EoAdv\atl90.dll
C:\Program Files\EoRezo\EoAdv\EoAdv.dll
C:\Program Files\EoRezo\EoAdv\mfc90.dll
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.ATL.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.CRT.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.MFC.manifest
C:\Program Files\EoRezo\EoAdv\msvcr90.dll
C:\Program Files\EoRezo\lang\ihm_eoclock.xml
C:\Program Files\EoRezo\lang\ihm_eoengine.xml
C:\Program Files\EoRezo\lang\ihm_eonet.xml
C:\Program Files\EoRezo\lang\ihm_eorezotools.xml
C:\Program Files\EoRezo\lang\ihm_eosudoku.xml
C:\Program Files\EoRezo\lang\ihm_eoweather.xml
C:\Program Files\EoRezo\lang\lang_en.xml
C:\Program Files\EoRezo\lang\lang_es.xml
C:\Program Files\EoRezo\lang\lang_fr.xml
C:\Program Files\EoRezo\lang\lang_it.xml
C:\Program Files\EoRezo
C:\Users\Elise\AppData\Roaming\Microsoft\Windows\Cookies\elise@partypoker[1].txt

(!) -- Fichiers temporaires supprimés.

.
+-----------------| Scan additionnel:
.

---- Mozilla FireFox Version 2.0 ----

Nom du profil: yujm4tz1.default (Elise)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://lo.st#home");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.msn.fr/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.msn.fr/");
(Prefs.js) user_pref("browser.startup.homepage"\÷, "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.msn.fr/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.msn.fr/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.msn.fr/");
(Prefs.js) user_pref("browser.startup.homepage"\÷"http:Øú//frØú.msnØú.comØú/");ú
(Prefs.js) usØúÑer_pØúÑref(úq"keyú‚wordØúâ.URLØú", "ØúâhttpØúÀ://seØúçarc\÷user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://fr.msn.com/");
.
(prefs.js) EFFACÉ: user_pref("browser.startup.homepage", "hxxp://lo.st#home");
.

---- Internet Explorer Version 8.0.6001.18702 ----

[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Start Page: hxxp://fr.msn.com/?ocid=iehp

[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: res://ieframe.dll/tabswelcome.htm

=========== Suspect (Cracks, Serials ... ) ==========

.
C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9653-to-3.1.0.9767-frFR-patch.exe
[7151768 Octet(s)|--a------|16/04/2009 13:30|HashMD5: 5e4f3f7da0778417e9b37d2c036a9947 |CRC32: 458c4948]


+---------------------------------------------------------------------------+

8506 Octet(s) - C:\Ad-Report-30.05.2009.log

19 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
51 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE

Fin à: 21:05:43 | 30/05/2009
.
+-----------------| E.O.F
.
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 21:51
EDIT:

Supprime Ad-Remover:

▶ Relance "Ad-remover" : au menu principal choisis l'option "D"
▶Une fenêtre d’avertissement va alors s’ouvrir : clique sur OK

Relances Hijackthis en faisant Do a system scan only, coche ces lignes:

O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O8 - Extra context menu item: &Download by NetAnts - C:\PROGRA~1\NetAnts\NAGet.htm
O8 - Extra context menu item: Download &All by NetAnts - C:\PROGRA~1\NetAnts\NAGetAll.htm
O9 - Extra button: NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe
O9 - Extra 'Tools' menuitem: &NetAnts - {57E91B47-F40A-11D1-B792-444553540000} - C:\PROGRA~1\NetAnts\NetAnts.exe

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab


puis clique sur Fix checked

Va voir si tu fichiers sont encore présents:

c:\program files\eorezo\eoadv\eorezobho.dll
c:\program files\eorezo\eoengine.exe
c:\program files\netants\naget.htm
c:\program files\netants\nagetall.htm


si oui, tu les vires.



As-tu fais cette étape (avec le bloc-notes):

http://www.commentcamarche.net/forum/affich 12564133 ordinateur viruse?page=2#25

Je t'avais contacté par MP mais visiblement, tu ne l'as pas vu.
0
ok, je ferais cette partie demain si je peux. Il reste encore beaucoup de manip à faire?
0
Nic00 Messages postés 1701 Date d'inscription lundi 25 août 2008 Statut Membre Dernière intervention 30 mars 2010 95
30 mai 2009 à 22:24
Normalement non.

Tu n'as toujours pas répondu à ma question :

As-tu fais cette étape (avec le bloc-notes):

http://www.commentcamarche.net/forum/affich 12564133 ordinateur viruse?page=2#25

A demain ;-)
0