Scache eorezo toujours

Résolu
Bonjour,
Jai fait tout le nécessaire pour etre débarasséé de eorezo, seulement, il est toujours sur mon ordi...

y a t'il quelque chose à faire svp ?? j'en peux plus de ce site !

merci
Configuration: Windows Vista
Firefox 2.0.0.20

26 réponses

Résumé de la discussion

Un utilisateur Windows Vista cherche à se débarrasser d'EoRezo, une menace persistance sur l'ordinateur malgré des tentatives de nettoyage, et demande des conseils pratiques pour éliminer complètement l'infection. Le conseil retenu propose une désinstallation manuelle puis l'usage de CCleaner et Malwarebytes, avec nettoyage des fichiers temporaires et du registre, répétant l'opération plusieurs fois et activant le nettoyage automatique au démarrage. D'autres réponses évoquent des outils supplémentaires et des procédures administratives, incluant l'exécution des programmes en tant qu'administrateur et la génération de rapports d'analyse pour vérification. En dernier, le fil illustre l'importance d'un suivi antivirus et de vérifications système complémentaires, les échanges revenant sur les garanties de suppression et les risques résiduels si des composants persistent.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    salut

    A)- Tu utilises vista, tu dois donc aussi désactiver l'UAC avant d'utiliser ce logiciel.
    Regarde ici pour savoir comment désactiver l'UAC sous vista ==> ICI
    http://bibou0007.com/windows-vista-f102/tutorial-desactiver-l-uac-sur-vista-t132.htm

    le logiciel est à exécuter en mode administrateur en faisant un clic-droit sur le raccourci / "Exécuter en tant qu'administrateur".

    Télécharges http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe ( de Cyrildu17 / C_XX ) sur ton bureau :

    /!\ Déconnectes toi et fermes toutes applications en cours

    ●un clic-droit sur le programme d'installation ,et "Exécuter en tant qu'administrateur". et installe le dans son emplacement par défaut. ( C:\Program files )
    ● clic-droit sur le raccourci Ad-remover située sur ton bureau et "Exécuter en tant qu'administrateur"
    ● Au menu principal choisi l'option "L"
    ● Postes le rapport qui apparait à la fin .

    ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
    2
    1. Contributeur sécurité
      en va désinstaller tout sa manuellement via ajout et suppression programme

      tu garde juste malwarbyte et ccleaner

      après avoir désinstaller les outils qui nous ont servit

      tu téléchargera Ccleaner https://www.ccleaner.com/ccleaner/download

      ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

      . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
      Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
      . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

      Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

      içi mode d'emploi pour ccleaner

      https://www.malekal.com/tutoriel-ccleaner/

      Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
      Mais C.. de penser que ­tu es libre...Merci a australe13
      2
      1. Contributeur sécurité
        tu a fait avec un clic droit et exécute en tant qu'administrateur
        1
        1. voila le rapport..jespère etre tranquille cette fois !! merci en tout cas ;)
          ======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
          .
          Mit à jour par C_XX le 24/06/2009 à 7:10 PM
          Contact: AdRemover.contact@gmail.com
          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
          .
          Lancé à: 22:00:21, 17/07/2009 | Mode Normal | Option: CLEAN
          Exécuté de: C:\Program Files\Ad-remover\
          Système d'exploitation: Microsoft® Windows Vista™ Home Basic Service Pack 1 v6.0.6001
          Nom du PC: PC-DE-ELO | Utilisateur actuel: Elo
          .
          Administrateur: Administrateur *Desactive*
          Administrateur: Elo
          N'est pas administrateur: Invité *Desactive*
          .
          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
          .
          .
          HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
          HKCU\Software\EoRezo
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
          HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
          .
          C:\Users\Elo\AppData\Roaming\EoRezo\cache
          C:\Users\Elo\AppData\Roaming\EoRezo\cmhost.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\ConfMedia.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\db
          C:\Users\Elo\AppData\Roaming\EoRezo\eoDesktop
          C:\Users\Elo\AppData\Roaming\EoRezo\eoStats
          C:\Users\Elo\AppData\Roaming\EoRezo\host.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\install.exe
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate
          C:\Users\Elo\AppData\Roaming\EoRezo\user.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\eoDesktop\config.xml
          C:\Users\Elo\AppData\Roaming\EoRezo\eoDesktop\eoDesktop.html
          C:\Users\Elo\AppData\Roaming\EoRezo\eoDesktop\userConfig.xml
          C:\Users\Elo\AppData\Roaming\EoRezo\eoStats\eoStats.txt
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\Download
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\help_config.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\Software
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.dat
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.exe
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\user_config.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo\SoftwareUpdate\user_profil.cyp
          C:\Users\Elo\AppData\Roaming\EoRezo
          C:\Windows\Prefetch\SOFTWAREUPDATEHP.EXE-B9999561.pf

          (!) -- Fichiers temporaires supprimés.

          .
          ============== Scan additionnel ==============
          .

          * Mozilla FireFox Version 2.0.0.20 *

          Nom du profil: dg7fl8qs.default (Elo)
          .
          (Prefs.js) user_pref("browser.search.defaultenginename", "Gdark");
          (Prefs.js) user_pref("browser.search.selectedEngine", "Gdark");
          (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q=");
          (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr");
          (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.20");
          .
          .

          * Internet Explorer Version 8.0.6001.18783 *

          [HKEY_CURRENT_USER\..\Internet Explorer\Main]

          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
          Search Page: hxxp://fr.gdark.com
          Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search bar: hxxp://search.msn.com/spbasic.htm
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Start Page: hxxp://fr.msn.com/

          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

          Tabs: res://ieframe.dll/tabswelcome.htm

          ============== Suspect (Cracks, Serials ... ) ==============

          .
          .
          ===================================
          .
          3810 Octet(s) - C:\Ad-Report-CLEAN.log
          2832 Octet(s) - C:\Ad-Report-SCAN.log
          .
          111 Fichier(s) - C:\Users\Elo\AppData\Local\Temp
          1 Fichier(s) - C:\Windows\Temp
          .
          20 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
          16 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
          .
          Fin à: 22:18:38 | 17/07/2009
          .
          ============== E.O.F ==============
          .
          0
          1. Contributeur sécurité
            poste un rapport hijackthis (outil de diagnostic)
            Télécharge http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

            --) Enregistre HJTInstall.exe sur ton bureau
            --) Double-clique sur HJTInstall.exe pour lancer le programme
            --) Par défaut, il s'installera içi C:\Programme Files\Trend Micro\HijackThis
            --) Accepte la license en cliquant sur le bouton "I Accept"
            --) Choisis l'option "Do a system scan and save a log file"
            --) Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
            --) Clique sur "Édition -> Sélectionner tout", puis sur "Édition -> Copier" pour copier tout le contenu du rapport
            --) Colle le rapport que tu viens de copier sur ce forum
            --) Ne fixe encore AUCUNE ligne,
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:33:27, on 17/07/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\ASUS\ASUS Live Update\ALU.exe
              C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
              C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
              C:\Program files\P4G\BatteryLife.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe
              C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe
              C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
              C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
              C:\Program Files\Elantech\ETDCtrl.exe
              C:\Program Files\ASUS\ATK Media\DMedia.exe
              C:\Program Files\Windows Live\Family Safety\fsui.exe
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
              C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
              C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\explorer.exe
              C:\Windows\system32\notepad.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\Windows\system32\NOTEPAD.EXE
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe"
              O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\ASUSTek\ASUSDVD 8\Language\Language.exe"
              O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe"
              O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
              O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
              O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
              O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
              O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
              O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
              O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
              O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
              O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
              O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKCU\..\Run: [SRS Premium Sound] "C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe" /hideme
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: BTTray.lnk = ?
              O4 - Global Startup: FancyStart daemon.lnk = ?
              O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
              O13 - Gopher Prefix:
              O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
              O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
              O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
              O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
              O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
              O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
              O23 - Service: SRS Volume Sync Service (SRS_VolSync_Service) - SRS Labs, Inc. - C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe
              O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:33:27, on 17/07/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
                C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
                C:\Program files\P4G\BatteryLife.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe
                C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe
                C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
                C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                C:\Program Files\Elantech\ETDCtrl.exe
                C:\Program Files\ASUS\ATK Media\DMedia.exe
                C:\Program Files\Windows Live\Family Safety\fsui.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
                C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\explorer.exe
                C:\Windows\system32\notepad.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Windows\system32\NOTEPAD.EXE
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Windows\system32\SearchFilterHost.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe"
                O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\ASUSTek\ASUSDVD 8\Language\Language.exe"
                O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe"
                O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
                O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
                O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
                O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
                O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
                O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
                O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
                O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
                O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
                O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKCU\..\Run: [SRS Premium Sound] "C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe" /hideme
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Global Startup: BTTray.lnk = ?
                O4 - Global Startup: FancyStart daemon.lnk = ?
                O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                O13 - Gopher Prefix:
                O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
                O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                O23 - Service: SRS Volume Sync Service (SRS_VolSync_Service) - SRS Labs, Inc. - C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe
                O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                0
                1. il me met hijack is already running..que faire svp???
                  0
                  1. Contributeur sécurité
                    Telecharge maintenant FindyKill sur ton bureau :
                    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                    --> Lance l installation avec les parametres par default

                    --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                    --> Choisi executer en tant qu administrateur

                    --> Au menu principal,choisi l option 1 (Recherche)

                    --> Post le rapport FindyKill.txt

                    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                    Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                    Mais C.. de penser que ­tu es libre...Merci a australe13
                    0
                    1. ############################## | FindyKill V5.003 |

                      # User : Elo (Administrateurs) # PC-DE-ELO
                      # Update on 17/07/09 by Chiquitine29
                      # Start at: 14:31:00 | 18/07/2009
                      # Website : http://pagesperso-orange.fr/NosTools/index.html

                      # AMD Athlon(tm) X2 Dual-Core QL-64
                      # Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
                      # Internet Explorer 8.0.6001.18783
                      # Windows Firewall Status : Enabled

                      # C:\ # Disque fixe local # 116,44 Go (80,39 Go free) [VistaOS] # NTFS
                      # D:\ # Disque fixe local # 104,73 Go (104,69 Go free) [DATA] # NTFS
                      # E:\ # Disque CD-ROM

                      ############################## | Processus actifs |

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\AUDIODG.EXE
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                      C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Windows\system32\WLANExt.exe
                      C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                      C:\Program files\P4G\BatteryLife.exe
                      C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
                      C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
                      C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
                      C:\Program Files\ASUS\ATK Hotkey\HControl.exe
                      C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
                      C:\Program Files\ASUS\Splendid\ACMON.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe
                      C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
                      C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe
                      C:\Windows\System32\ACEngSvr.exe
                      C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
                      C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                      C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
                      C:\Program Files\ASUS\ATK Hotkey\WDC.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                      C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Windows\servicing\TrustedInstaller.exe
                      C:\Program Files\Elantech\ETDCtrl.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\ASUS\ATK Media\DMedia.exe
                      C:\Program Files\Windows Live\Family Safety\fsui.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Windows\system32\conime.exe

                      ################## | C: |

                      ################## | C:\Windows |

                      ################## | C:\Windows\system32 |

                      ################## | C:\Windows\system32\drivers |

                      ################## | C:\Users\Elo\AppData\Roaming |
                      0
                      1. Contributeur sécurité
                        ! Déconnecte toi et ferme toutes applications en cours !

                        • Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'instalation par défaut .

                        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                        --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                        --> Choisi exécuter en tant qu'administrateur

                        • Choisis l'option 3 ( Vaccination )

                        • Laisse travailler l'outil.

                        • Ensuite post le rapport FindyKill.txt qui apparaitra.

                        • Note : Le rapport FindyKill.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                        0
                        1. ############################ | FindyKill V5.003 |

                          # User : Elo (Administrateurs) # PC-DE-ELO
                          # Update on 17/07/09 by Chiquitine29
                          # Start at: 21:36:50 | 18/07/2009
                          # Website : http://pagesperso-orange.fr/NosTools/index.html

                          # AMD Athlon(tm) X2 Dual-Core QL-64
                          # Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
                          # Internet Explorer 8.0.6001.18783
                          # Windows Firewall Status : Enabled

                          # C:\ # Disque fixe local # 116,44 Go (80,39 Go free) [VistaOS] # NTFS
                          # D:\ # Disque fixe local # 104,73 Go (104,69 Go free) [DATA] # NTFS
                          # E:\ # Disque CD-ROM
                          # F:\ # Disque amovible # 962,07 Mo (905,37 Mo free) # FAT32

                          ############################## | Processus actifs |

                          C:\Windows\System32\smss.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\AUDIODG.EXE
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                          C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                          C:\Windows\system32\WLANExt.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                          C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
                          C:\Program files\P4G\BatteryLife.exe
                          C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
                          C:\Program Files\ASUSTek\ASUSDVD 8\PDVD8Serv.exe
                          C:\Program Files\ASUS\ATK Hotkey\HControl.exe
                          C:\Program Files\Cyberlink\Power2Go\CLMLSvc.exe
                          C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
                          C:\Program Files\ASUS\Splendid\ACMON.exe
                          C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                          C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                          C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
                          C:\Windows\System32\ACEngSvr.exe
                          C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
                          C:\Program Files\ASUS\ATK Hotkey\WDC.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Windows\servicing\TrustedInstaller.exe
                          C:\Program Files\Elantech\ETDCtrl.exe
                          C:\Program Files\ASUS\ATK Media\DMedia.exe
                          C:\Program Files\Windows Live\Family Safety\fsui.exe
                          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                          C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          ################## | C: |

                          ################## | C:\Windows |

                          ################## | C:\Windows\system32 |

                          ################## | C:\Windows\system32\drivers |

                          ################## | C:\Users\Elo\AppData\Roaming |

                          ################## | C:\Users\Elo\Temporary Internet Files |

                          ################## | Registre / Clés infectieuses |

                          ################## | Etat / Services / Informations |

                          # Affichage des fichiers cachés : OK

                          # Mode sans echec : OK

                          # Uac : OK

                          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                          # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                          # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
                          # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                          # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                          ################## | Cracks / Keygens / Serials |

                          ################## | ! Fin du rapport # FindyKill V5.003 ! |
                          0
                          1. Contributeur sécurité
                            OK

                            il a était modifier la vaccination se fait en passant par l'option 2

                            Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                            Mais C.. de penser que ­tu es libre...Merci a australe13
                            0
                            1. jai pas eu le rapport apres le nettoyage.. il a redemarré mon ordi, je l'ai pas ...
                              0
                              1. Contributeur sécurité
                                le rapport FindyKill.txt est sauvegardé a la racine du disque
                                0
                                1. si jai pas le rappart, cest pas grave ? il y a autre chose à faire apres ou ceest fini?? merci 1000fois en tout cas =)
                                  0
                                  1. Contributeur sécurité
                                    non c'est pas grave mais je voulait voir si la vaccination de tes lecteur avait bien était fait pour voir s'il y'a eu aucun bug pendant l'opération

                                    télécharge malwarbyte http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebytes anti malware

                                    a l'installation vérifie que mise a jour et lancer programme et scan complet sont bien cocher


                                    Une fois a jour, le programme va se lancer; clic sur l´onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

                                    A la fin du scan clique sur Afficher les résultats

                                    Suppression des éléments détectés >>>> clique sur Supprimer la sélection ou supprimer tout
                                    S'il t'es demandé de redémarrer >>> clique sur "Yes"


                                    Et tu poste le rapport générer
                                    0
                                    1. le rapport de malware :

                                      Malwarebytes' Anti-Malware 1.39
                                      Version de la base de données: 2421
                                      Windows 6.0.6001 Service Pack 1

                                      18/07/2009 22:41:27
                                      mbam-log-2009-07-18 (22-41-27).txt

                                      Type de recherche: Examen complet (C:\|D:\|F:\|)
                                      Eléments examinés: 172430
                                      Temps écoulé: 28 minute(s), 1 second(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 0

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      0
                                      1. Contributeur sécurité
                                        bonjour

                                        pour nettoyer les fix qui ont servit

                                        Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
                                        http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner

                                        Double clique sur ToolsCleaner2.exe >
                                        puis Recherche
                                        et sur Suppression
                                        Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                                        CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                                        Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                                        Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                                        tu poste le rapport générer après suppression
                                        0
                                        • 1
                                        • 2