HClean : comment s'en débarrasser ???

Fermé
Naouel - 29 sept. 2005 à 22:11
 Naouel - 9 oct. 2005 à 16:57
Bonjour,

Je n'arrive pas à supprimer le virus HClean sur mon ordinateur.
Je suis desespérée... je ne sais plus quoi faire et je voudrais vraiment éviter de formater mon portable...

Pourriez vous m'aider ?

Je n'y connais pas grand chose alors j'espère que ça ne sera pas trop compliqué.

Voilà ce que j'ai déjà fait:

-analyse Norton antivirus mais il n'arrive pas à supprimer HClean
-Ad Aware SE bloque également dès qu'il tombe sur HClean
-CleanUp! n'a rien trouvé meme en mode sans echec
-a² StartCenter n'est pas efficace non plus
-spybot search and destroy ne trouve pas le virus
-spyware blaster non plus
-ccleaner non plus


Voici les rapports qui pourront peut etre apporter plus de renseignements:


Logfile of HijackThis v1.99.1
Scan saved at 22:03:53, on 29/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\MPB.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\PL15Co2K.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\Extrafilm FotoFacil\Agent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Symantec Shared\NMain.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Naouel\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avacreat.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\syekk.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\syekk.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MPB] C:\WINDOWS\System32\MPB.exe
O4 - HKLM\..\Run: [Microsoft Windows Update] msoffice2.exe
O4 - HKLM\..\Run: [Microsoft Features] ms32cfg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [XML Service] msxml.exe
O4 - HKLM\..\Run: [wvsvc] wvsvc.exe
O4 - HKLM\..\Run: [WIN USB 2.0] winusb.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [Video Process] xxyvher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Nvidia Control Panel] ncsvc32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Windows Securety] wurguar.exe
O4 - HKLM\..\Run: [Microsoft Services] lssrv.exe
O4 - HKLM\..\Run: [HI-SPEED USB DEVICE Coinstaller] PL15Co2K.exe
O4 - HKLM\..\Run: [CRC Value Verifier] crsss32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [ExtraFilmHemmaAgent] "C:\Program Files\Extrafilm FotoFacil\Agent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [WIN USB 2.0] winusb.exe
O4 - HKLM\..\RunServices: [Video Process] xxyvher.exe
O4 - HKLM\..\RunServices: [wvsvc] wvsvc.exe
O4 - HKLM\..\RunServices: [Windows Update] host32.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Update] msoffice2.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Securety] wurguar.exe
O4 - HKLM\..\RunServices: [Microsoft Features] ms32cfg.exe
O4 - HKLM\..\RunServices: [Nvidia Control Panel] ncsvc32.exe
O4 - HKLM\..\RunServices: [CRC Value Verifier] crsss32.exe
O4 - HKLM\..\RunServices: [XML Service] msxml.exe
O4 - HKLM\..\RunServices: [Microsoft Services] lssrv.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\RunServices: [Video Process] xxyvher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://kt.bar.need2find.com/KT/menusearch.html?p=KT
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097671816628
O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) - http://mypixmania.com/fr/fr/tools/activex/fpu.cab
O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://asp02.photoprintit.de/microsite/3462/defaults/activex/IPSUploader.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E279B4B-BCC0-479A-AF58-80AF322F8285}: NameServer = 69.50.168.178 85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3157E16-1D06-4B34-9570-8E2ACE98842A}: NameServer = 69.50.168.178,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{F208712A-72DC-49A9-BF90-91BB38C8B784}: NameServer = 69.50.168.178,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD2DC2F4-A141-484A-9939-C545335C9E00}: NameServer = 69.50.168.178,85.255.112.16
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Microsoft Windows Securety (Securety) - Unknown owner - C:\WINDOWS\System32\wurguar.exe" -netsvcs (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe








---------------------------------------------------------

Rapport fait à 21:44:24,86 le 29/09/2005
Executé à partir de C:\Documents and Settings\Naouel\Mes documents\AUTRES\Internet
OS: Microsoft Windows XP [version 5.1.2600]

*********************************************

Vérification HKLM\...\...\...\...\ruins

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
"pgtshlld"=hex:40,0f,00,00,31,31,09,05,06,09,62,7d,bb,78,5d,48,14,00,00,00
"nidnsdr"=hex:c8,10,00,00,af,b1,9e,9b,99,8c,f3,3b,f8,9d,c8,13,00,00,00
"23naelch"=hex:6c,11,00,00,41,52,7d,7c,78,67,5a,53,4f,0c,01,3c,14,00,00,00
"aplnsftn"=hex:55,13,00,00,56,54,1e,65,76,7c,00,7b,56,67,28,57,14,00,00,00
"23rtcdaol"=hex:a1,53,00,00,98,8d,a7,a8,b1,a8,d6,19,06,12,e3,f4,f3,15,00,00,00
"7"=hex:50,2a,00,00,2d,2e,19,18,04,03,46,4f,ab,68,2d,58,14,00,00,00
"8"=hex:50,2a,00,00,57,29,66,13,01,04,7b,b3,60,15,50,13,00,00,00
"9"=hex:50,2a,00,00,2b,59,13,6e,0b,01,05,7c,ab,68,2d,58,14,00,00,00
"1dedoc"=hex:f7,1b,00,00,cf,fb,fe,f1,ee,95,e0,91,ba,81,12,00,00,00
"llams_ogol"=hex:9a,1c,00,00,93,94,a4,a4,4c,b0,c2,36,d3,db,2d,12,e7,02,16,00,\
00,00
"repiwh"=hex:8e,0d,00,00,63,98,52,53,46,bd,79,3e,d3,2e,12,00,00,00
"domdnb"=hex:07,1f,00,00,fc,e8,ce,d9,c3,d6,f0,a1,aa,b1,12,00,00,00
"orcimlh"=hex:ef,1f,00,00,c2,c6,f9,f5,e7,dc,9b,d0,81,ba,b1,13,00,00,00
"23tsniow"=hex:0a,58,00,00,14,e4,d6,d5,c8,c3,f8,f1,ed,b2,67,82,14,00,00,00
"flmmd"=hex:0a,39,00,00,fb,ea,d2,db,c5,85,aa,4f,ba,11,00,00,00
"16"=hex:3c,65,00,00,31,02,0d,0c,28,17,aa,a3,bf,7c,51,4c,14,00,00,00
"17"=hex:3c,65,00,00,3b,3d,0a,07,15,18,6f,a7,74,69,44,13,00,00,00
"18"=hex:3c,65,00,00,3f,2d,07,02,1f,15,69,50,bf,7c,51,4c,14,00,00,00
"19"=hex:2c,44,00,00,01,12,3d,3c,38,27,9a,93,8f,4c,41,7c,14,00,00,00
"20"=hex:2c,44,00,00,0b,0d,3a,37,25,28,5f,97,44,79,74,13,00,00,00
"21"=hex:2c,44,00,00,0f,3d,37,32,2f,25,59,40,8f,4c,41,7c,14,00,00,00
"22"=hex:64,5c,00,00,59,5a,75,64,70,6f,52,5b,47,14,39,24,14,00,00,00
"23"=hex:85,5c,00,00,62,74,5d,5e,5c,53,36,7e,3f,20,0f,13,00,00,00
"24"=hex:85,5c,00,00,66,64,4e,55,46,4c,30,2b,66,37,18,07,14,00,00,00
"25"=hex:e7,1e,00,00,da,d7,f6,e1,fd,e8,df,d4,c0,91,ba,a1,14,00,00,00
"26"=hex:e7,1e,00,00,cc,d6,ff,f8,fe,ed,90,d8,99,82,a9,13,00,00,00
"27"=hex:07,1f,00,00,e0,e6,c8,d7,c0,ce,b2,a5,e0,b1,9a,81,14,00,00,00
"28"=hex:ed,6f,00,00,c0,cd,fc,ff,fb,e6,e5,d2,ce,8f,80,bf,14,00,00,00
"29"=hex:ed,6f,00,00,ca,cc,c5,f6,e4,eb,9e,d6,87,b8,b7,13,00,00,00
"30"=hex:0d,70,00,00,ee,1c,d6,2d,ce,c4,b8,a3,ee,af,60,9f,14,00,00,00
"31"=hex:57,08,00,00,2a,27,66,11,0d,78,4f,44,50,61,2a,51,14,00,00,00
"32"=hex:78,08,00,00,7f,41,4e,4b,69,5c,23,6b,08,2d,38,13,00,00,00
"33"=hex:78,08,00,00,73,71,7b,46,53,59,2d,14,73,00,15,30,14,00,00,00
"34"=hex:41,71,00,00,3c,39,08,0b,17,12,b1,be,ba,7b,5c,4b,14,00,00,00
"35"=hex:61,71,00,00,46,58,71,62,70,77,0a,42,13,04,23,13,00,00,00
"36"=hex:82,71,00,00,65,6b,4d,58,45,53,37,2e,65,3a,1f,0a,14,00,00,00
"37"=hex:00,07,00,00,fd,fe,c9,c8,d4,d3,f6,ff,fb,b8,9d,88,14,00,00,00
"38"=hex:a4,07,00,00,83,95,b2,bf,bd,b0,d7,1f,dc,c1,ec,13,00,00,00
"39"=hex:93,0a,00,00,94,9a,5c,ab,b4,42,c6,39,14,25,ee,15,14,00,00,00
"40"=hex:18,59,00,00,15,e6,21,d0,cc,3b,8e,87,93,a0,75,90,14,00,00,00
"41"=hex:39,59,00,00,3e,00,09,0a,28,1f,62,aa,4b,6c,7b,13,00,00,00
"42"=hex:39,59,00,00,32,30,3a,01,12,18,6c,57,b2,43,54,73,14,00,00,00
"43"=hex:31,30,00,00,0c,09,38,3b,27,22,a1,ae,8a,4b,4c,7b,14,00,00,00
"44"=hex:52,30,00,00,51,2b,60,6d,03,06,05,4d,62,17,52,13,00,00,00
"45"=hex:72,30,00,00,75,7b,7d,48,55,63,27,1e,75,0a,0f,3a,14,00,00,00
"46"=hex:dc,58,00,00,d1,a2,ed,ec,88,f7,ca,c3,df,9c,b1,ac,14,00,00,00
"47"=hex:fd,58,00,00,fa,fc,d5,c6,d4,db,ae,e6,b7,a8,87,13,00,00,00
"48"=hex:1d,59,00,00,1e,0c,26,3d,3e,34,48,b3,9e,5f,70,6f,14,00,00,00
"49"=hex:7e,2b,00,00,73,7c,4f,4e,6a,51,74,7d,79,3e,13,0e,14,00,00,00
"50"=hex:4d,2e,00,00,2a,2c,65,16,04,0b,7e,b6,67,18,57,13,00,00,00
"51"=hex:cf,2e,00,00,a8,de,90,ef,88,86,fa,fd,28,e9,a2,d9,14,00,00,00
"52"=hex:cd,58,00,00,a0,ad,9c,9f,9b,86,c5,32,2e,ef,a0,df,14,00,00,00
"53"=hex:d2,59,00,00,d1,ab,e0,ed,83,86,85,cd,e2,97,d2,13,00,00,00
"54"=hex:13,5a,00,00,14,1a,dc,2b,34,c2,46,b9,94,a5,6e,95,14,00,00,00
"55"=hex:63,15,00,00,5e,5b,6a,65,71,6c,53,58,44,15,3e,25,14,00,00,00
"56"=hex:84,15,00,00,63,75,52,5f,5d,50,37,7f,3c,21,0c,13,00,00,00
"57"=hex:c5,15,00,00,a6,a4,8e,95,86,8c,f0,eb,26,f7,d8,c7,14,00,00,00
"58"=hex:53,46,00,00,2e,2b,1a,15,01,7c,43,48,54,65,2e,55,14,00,00,00
"59"=hex:95,46,00,00,92,64,ad,ae,4c,43,c6,0e,2f,d0,1f,13,00,00,00
"60"=hex:17,47,00,00,10,16,d8,27,30,3e,42,b5,90,a1,6a,91,14,00,00,00
"61"=hex:16,10,00,00,eb,e4,27,d6,c2,39,8c,85,91,a6,6b,96,14,00,00,00
"62"=hex:58,10,00,00,5f,21,6e,6b,09,7c,03,4b,68,0d,58,13,00,00,00
"63"=hex:99,10,00,00,92,90,5a,a1,b2,b8,cc,37,12,23,f4,13,14,00,00,00


*********************************************

Fichiers détectés :

C:\WINDOWS\balloon.wav Présent !

*********************************************

Recherche des processus aleatoires
d'après les modèles : cs***.exe, dm***.exe, ya***.exe

C:\WINDOWS\System32
dmcpl.exe

*********************************************

Recherche presence hclean32.exe...
non trouvé...





Merci pour toute l'aide que vous pourrez m'apporter.......

Naouel

41 réponses

Utilisateur anonyme
9 oct. 2005 à 16:40
peut etre que ca viens d'un parametrage à faire (firewall ou neuf box) ?

dsl, mais je ne suis pas tres calé en configuration de materiel.
essaye de poster un message sur les forums internet ou materiel, peut etre que quelqu'un qui à eu le meme prob pourra te renseigner mieux que moi.

a++
0
Merci beaucoup pour ton aide en tout cas.
C'est très sympa et très utile d'avoir des personnes qui prennent le temps d'aider les autres.

A +
0