Virus ?

Fermé
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 - 9 oct. 2009 à 01:58
 Utilisateur anonyme - 12 oct. 2009 à 14:10
Bonjour,
je poste ce sujet car je pense que mon os contient peut etre un virus.

J'ai suivi les consignes contennu dans ce sujet :
https://www.commentcamarche.net/faq/2490-supprimer-les-adwares-publicites-intempestives-pop-up-etc

Merci d'avance à ceux qui m'aideront.

Voilà donc les deux rapports :
- log :

Logfile of random's system information tool 1.06 (written by random/random)
Run by Ffayce at 2009-10-09 01:42:47
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 113 GB (50%) free of 227 GB
Total RAM: 3069 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:43:22, on 09/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpressServer.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\conime.exe
C:\Program Files\SGPSA\ie3sh.exe
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\explorer.exe
C:\Program Files\Ubisoft\YouUp\Youup.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\system32\taskeng.exe
C:\Users\Ffayce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S6G7UI9D\RSIT[1].exe
C:\Program Files\trend micro\Ffayce.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] Search Guard Plus Updater] cmd.exe /C RD /S /Q C:\PROGRA~1\SEARCH~2
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] Search Guard Plus] cmd.exe /C RD /S /Q C:\PROGRA~1\SEARCH~1
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] Fast Browser Search] cmd.exe /C RD /S /Q C:\PROGRA~1\FASTBR~1
O4 - HKLM\..\RunOnce: [DeleteDir[CD8] SGPSA] cmd.exe /C RD /S /Q C:\PROGRA~1\SGPSA
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Recherche AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_3_0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\STacSV.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: YouupServiceWinService - Unknown owner - C:\Users\Ffayce\AppData\Local\Temp\YouUpService\YouupService.exe
A voir également:

41 réponses

ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 17:43
oui j'ai essayer de desinstaller et réinstaller le pilote audio mais je m'y suis peut être mal pris
0
Utilisateur anonyme
10 oct. 2009 à 17:56
Ressaye,

Tu le désinstalle puis tu supprime son dossier qui normalement ce trouve dans programmes files, tu réinstalle le nouveau en faisant une détéction automatique ici ...

Faut redémarrer à chaque désinstallation ou installation du pilote !
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 20:57
et le dernier rapport malwarebytes :

Malwarebytes' Anti-Malware 1.41
Version de la base de données: 2937
Windows 6.0.6002 Service Pack 2

10/10/2009 20:54:51
mbam-log-2009-10-10 (20-54-51).txt

Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 449311
Temps écoulé: 2 hour(s), 57 minute(s), 14 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 8

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Program Files\Adobe\Adobe Photoshop CS4\PhotoShopCS4_X32_Crk.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Steinberg\Cubase SX 3\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Program Files\WinRAR\Patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\Program Files\Navilog1\gnc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Ffayce\AppData\Local\gnc.exe (Trojan.Dropper) -> Delete on reboot.
C:\Users\Ffayce\AppData\Local\Microsoft\gnc.exe (Trojan.Dropper) -> Delete on reboot.
C:\Users\Ffayce\AppData\Local\VirtualStore\Windows\System32\gnc.exe (Trojan.Dropper) -> Delete on reboot.
C:\Windows\System32\gnc.exe (Trojan.Dropper) -> Delete on reboot.
0
Utilisateur anonyme
10 oct. 2009 à 21:17
Vide la quarantaine de Malwarbyte's
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 21:29
c'est fait ensuite ?
0
Utilisateur anonyme
10 oct. 2009 à 21:41
Fait une analyse avec ton antivirus et supprime les infection trouver ...

Comment va l'ordinateur ?
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 21:45
ben là ça a l'air d'être bon, le seul problème qui réside encore c'est celui du son mais je n'ai pas encore essayé ce que tu m'as indiqué je vais le faire maintenant, j'te tiens au courant
0
Utilisateur anonyme
10 oct. 2009 à 22:04
Ok
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 22:19
tu peux me dire exactement comment faire pour déinstal le driver, je devrais y arriver en testant pls choses mais j'ai pas envi de faire de bétises
merci
0
Utilisateur anonyme
10 oct. 2009 à 22:25
Par ajout/supression de programmes,

après tu supprime son dossier qui se trouve dans le dossier programmes files
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 22:43
skuz moi hein mais comment je le reconnais dans ajout/suppres de prog ?
0
Utilisateur anonyme
10 oct. 2009 à 22:44
Bah c'est la marque du pilote de ta carte son ...

Je peux te dire sa moi je connait pas ton pc ...
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 23:28
c bon j'ai récuperé le son et tous semble fonctionner comme avant j'te remercie helper-mask
j'attends 15 min si tu as d'autres choses à me conseiller après je mets le sujet comme résolu

encore merci
0
Utilisateur anonyme
10 oct. 2009 à 23:46
Fait moi un rapport hijackthis ...
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
10 oct. 2009 à 23:52
voilà :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:51:00, on 10/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpressServer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Recherche AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_3_0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: YouupServiceWinService - Unknown owner - C:\Users\Ffayce\AppData\Local\Temp\YouUpService\YouupService.exe
0
Utilisateur anonyme
10 oct. 2009 à 23:57
Télécharge Superantispyware (SAS) en cliquant sur ce lien :

https://www.superantispyware.com/superantispywarefreevspro.html (à l'essai 15 jours)

Choisis "enregistrer" et enregistre-le sur ton bureau.

Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

Créé une icône sur le bureau.

Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.

- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

Dans la colonne de gauche, coche C:\Fixed Drive.

Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

Pour recopier les informations sur le forum, fais ceci :

- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

- Copie son contenu dans ta réponse.
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
11 oct. 2009 à 13:51
- Ce dernier scan a duré plus de 11h est ce normal ?

- Au redemarage j'ai eu à nouveau un message d'erreur "Team h20 cledx a cessé de fonctionner" qu'est ce que c'est ?

Voici le rapport :

SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 10/11/2009 at 01:35 PM

Application Version : 4.29.1002

Core Rules Database Version : 4158
Trace Rules Database Version: 2085

Scan type : Complete Scan
Total Scan Time : 11:58:11

Memory items scanned : 822
Memory threats detected : 0
Registry items scanned : 8226
Registry threats detected : 5
File items scanned : 1388980
File threats detected : 165

Adware.Tracking Cookie
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@weborama[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@aimfar.solution.weborama[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@atdmt[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@smartadserver[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@bs.serving-sys[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@msnportal.112.2o7[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@tradedoubler[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@microsoftwindows.112.2o7[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@serving-sys[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@xiti[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@bluestreak[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@youporn[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@ads-dev.youporn[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@advertising[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@interclick[1].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@doubleclick[2].txt
C:\Users\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@d2.advertserve[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@ads-dev.youporn[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@bluestreak[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@bs.serving-sys[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@d2.advertserve[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@interclick[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@serving-sys[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@tradedoubler[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\ffayce@youporn[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@ad.yieldmanager[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@ad.zanox[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@ads.urban-rivals[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@adserver.aol[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@adserver.aol[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@adtech[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@apmebf[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@bluestreak[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@boursoramabanque.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@boursoramabanque.solution.weborama[3].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@bouyguestelecom.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@content.yieldmanager[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@doubleclick[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@fr.at.atwola[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@fr.at.atwola[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@himedia.individuad[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@mediaplex[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@sfr.122.2o7[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@sfr.122.2o7[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@smartadserver[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@tradedoubler[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@weborama[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\AppData\Roaming\Microsoft\Windows\Cookies\Low\ffayce@xiti[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@ads-dev.youporn[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@bluestreak[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@bs.serving-sys[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@d2.advertserve[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@interclick[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@serving-sys[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@tradedoubler[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\ffayce@youporn[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@ad.yieldmanager[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@ad.zanox[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@ads.urban-rivals[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@adserver.aol[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@adserver.aol[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@adtech[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@apmebf[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@bluestreak[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@boursoramabanque.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@boursoramabanque.solution.weborama[3].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@bouyguestelecom.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@content.yieldmanager[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@doubleclick[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@fr.at.atwola[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@fr.at.atwola[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@himedia.individuad[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@mediaplex[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@sfr.122.2o7[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@sfr.122.2o7[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@smartadserver[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@tradedoubler[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@weborama[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\Application Data\Microsoft\Windows\Cookies\Low\ffayce@xiti[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@ads-dev.youporn[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@bluestreak[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@bs.serving-sys[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@d2.advertserve[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@interclick[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@serving-sys[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@tradedoubler[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\Cookies\ffayce@youporn[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@ad.yieldmanager[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@ad.zanox[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@ads.urban-rivals[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@adserver.aol[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@adserver.aol[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@adtech[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@advertising[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@aimfar.solution.weborama[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@apmebf[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@atdmt[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@atdmt[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@bluestreak[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@boursoramabanque.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@boursoramabanque.solution.weborama[3].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@bouyguestelecom.solution.weborama[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@content.yieldmanager[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@doubleclick[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@doubleclick[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@fr.at.atwola[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@fr.at.atwola[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@himedia.individuad[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@mediaplex[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@sfr.122.2o7[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@sfr.122.2o7[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@smartadserver[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@smartadserver[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@tradedoubler[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@weborama[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@weborama[2].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@xiti[1].txt
C:\Documents and Settings\Ffayce\Cookies\Low\ffayce@xiti[2].txt

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Adware.Vundo/Variant-MSFake
C:\PROGRAM FILES\NAVILOG1\REG.EXE
0
Utilisateur anonyme
12 oct. 2009 à 00:06
Bien !

Comment va l'ordinateur ?
0
ffayce Messages postés 244 Date d'inscription mercredi 9 avril 2008 Statut Membre Dernière intervention 9 octobre 2018 20
12 oct. 2009 à 03:43
Ben j'te dis au redemarage j'ai eu à nouveau un message d'erreur "Team h20 cledx a cessé de fonctionner" qu'est ce que c'est ?

Sinon tout semble bien fonctionner.
0
Utilisateur anonyme
12 oct. 2009 à 13:06
~~~~~~~~ ToolsCleaner ~~~~~~~~~~

► Installe sur ton bureaux Toolscleaner depuis le lien du haut

► Double-clique dessus, puis clique sur Recherche --> Le programme va chercher les utilitaires installés


((!)) Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal ! ((!))


Copie-colle le contenu du rapport qui apparait dans la fenêtre blanche.

Lorsque la recherche est terminée ToolsCleaner affiche une liste des différents outils trouvés, clique sur "Suppression" afin de les supprimer.

==> Vide ta corbeille
==> Quitte le programme

► Et enfin postes le rapport qui se trouve ici >>> C:\TCleaner.txt
0