Infrcte par virus win32.small.irm - Page 3

Précédent
  • 1
  • 2
  • 3
  1. booddha
     
    Tu as deux anti-virus sur la machine.

    Antivir version gratuite
    et KAPERSKI

    KAPERSKI tu l'as acheté ?
    0
  2. gigi
     
    Le PC va tres bien - jamais je n aurais cru ca possible- en tout cas merci beaucoup pour ton aide - tu es un heros informatique - mille fois MERCI
    0
  3. gigi
     
    non KASPERSKY je l'ai mis en mode évalution et ANTIVIR je croyais que je l'avais supprimé au profit de KASPERSKY
    0
  4. booddha
     
    Alors supprime KASPERSKY

    Demarrer --> Parametres --> Panneau de configuration -->> Ajout/suppression de programmes

    Cherche une ou des lignes (il peut y en avoir plusieurs) avec KASPERSKY.

    Sélectionne la ligne et click sur le bouton supprimer à droite.

    Répète pour chaque lignes.

    Previent moi quand fini

    La suite arrive
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. booddha
     
    Pour terminer

    Repasse un coup de CCleaner

    De la même façon que tu as supprimé KASPERSKY
    Supprime
    MSNFIX
    SDFIX
    COMBOFIX

    Si tu ne trouves pas une ou plusieurs de ces lignes, alors supprime les fichiers ou les répertoires en question là ou tu les as installés.

    Vide ta poubelle

    ======================= PareFeu XP - Vista ========================

    pour activer/désactiver le Pare-feu Xp http://www.libellules.ch/firewall_xpsp2.php

    Activer le pare-Feu si ce n'est déjà fait

    =========== POINT DE RESTAURATION SYSTEME =============

    * Désactivation :
    Clic droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
    • Appliquer
    • patienter jusqu’a ce que cela soit marqué "désactivé" puis Ok.

    * Activation :
    Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
    • Appliquer
    • patienter que cela soit à nouveau sur "surveillance" puis Ok.
    • Redémarrer l'ordinateur..

    ========================= AVG ANTI-SPYWARE ===============================
    Gratuit
    Merci à ep44 pour ce mode explicatif
    Télécharger:
    AVG-AntiSpyware http://download.grisoft.cz/filedir/inst/avgas-setup-7.5.1.43-3339.exe
    • Installer
    • Le lancer
    • Click : Mise à jour
    ------
    • Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    • Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

    • Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    • Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
    -------
    • Dans ANALYSE ( en forme de loupe )
    • Paramètres ==> sous COMMENT REAGIR==>click sur Actions recommandées ==>Quarantaine
    • Click : Analyse complète du système

    En fin de scan (C'est assez long suivant l'encombrement des disques)

    • Clic Appliquer toutes les actions <== ceci Très important
    • Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau
    -------
    • Relancer la machine en mode normal
    • Copier/coller le rapport ici

    ------------------------------- Antivir ----------------------------

    Clique droit sur le petit parapluie dans la barre de tâche en bas à droite.

    Cliquer sur Start Update

    Attendre que la mise à jour se termine

    Clique droit sur le petit parapluie dans la barre de tâche en bas à droite.

    S'assurer qu'il y a une coche devant Antivir Guard Enable. Si ce n'est pas le cas cliquer sur Antivir Guard Enable

    Toujours dans le même menu

    Click sur Start Antivir

    Antivir va scanné le système (C'est assez long suivant l'encombrement des disques). S'il trouve des Chose (petite sonnerie) Choisir delete.

    A la fin cliquer sur le bouton report

    Poster le rapport ici.

    Poste un rapport HitjackThis

    Et je pense que nous en aurons terminé mais attendre mon avis.
    0
  7. gigi
     
    je n ai pas COMBOFIX - SDFIX - MSNFIX dans le panneau de configuration ou je puisse les annuler - je ne les trouve que sur le bureau
    0
  8. gigi
     
    je reviens vers toi car je n ai pas réussi en mode sans échec à retrouver le chemin. La loupe est ce rechercher quand je fais demarrer ? Ensuite si je rentre la dedans je ne vois nulle part paramètres - comment réagir - ni la suite
    J'attends que tu m'eclaires - Merci
    0
  9. booddha
     
    Ca ne fait rien, tout ce qui est en mode sans échec, fais le en mode normal.

    Tient moi au courant
    0
  10. gigi
     
    ok mais ca ne me montre pas le chemin - j ai besoin d une marche à suivre plus détaillée - car meme en normal je ne trouve pas ou tu me dis d aller - Merci
    0
  11. booddha
     
    Tu veux faire quoi exactement, j'ai un peu perdu le fil.
    0
  12. gigi
     
    ca y est j ai reussi voila le rapport - excuse moi mais pour une neophyte la comprehension n est pas toujours celle du professur mais avec beaucoup d effort j y arrive -quand a avira antivir je ne l ai plus il faut que je le retelecharge -

    ---------------------------------------------------------
    AVG Anti-Spyware - Rapport d'analyse
    ---------------------------------------------------------

    + Créé à: 20:01:28 04/03/2008

    + Résultat de l'analyse:

    C:\Program Files\eMule\Incoming\Norton 2008 Anti virus suite KEY-GEN.zip/Norton 2008 Anti virus suite KEY-GEN.exe -> Backdoor.Rbot.eal : Nettoyé.
    C:\Program Files\eMule\Incoming\Norton 2008 Anti virus suite KEY-GEN\Norton 2008 Anti virus suite KEY-GEN.exe -> Backdoor.Rbot.eal : Nettoyé.
    C:\RECYCLER\S-1-5-21-761289612-1401638778-1328841865-1006\Dc2\MSNFix\03032008_18452979.zip/backup/Yazzle1560OinUninstaller.exe -> Not-A-Virus.Adware.PurityScan : Nettoyé.
    C:\RECYCLER\S-1-5-21-761289612-1401638778-1328841865-1006\Dc2\MSNFix\03032008_18452979\backup\Yazzle1560OinUninstaller.exe -> Not-A-Virus.Adware.PurityScan : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@adtech[1].txt -> TrackingCookie.Adtech : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@advertising[2].txt -> TrackingCookie.Advertising : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@adviva[2].txt -> TrackingCookie.Adviva : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@fastclick[2].txt -> TrackingCookie.Fastclick : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
    C:\Documents and Settings\ROGHI\Cookies\roghi@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.

    Fin du rapport
    0
  13. booddha
     
    Tu vois ça c'est le genre de chose qu'on attrape sur e-mule et compagnie.

    C:\Program Files\eMule\Incoming\Norton 2008 Anti virus suite KEY-GEN.zip/Norton 2008 Anti virus suite KEY-GEN.exe -> Backdoor.Rbot.eal

    C'est une porte dérobée à partir de laquelle un pirate peut faire ce qu'il veut de ton ordinateur, dont un ordinateur Zombie.

    C:\RECYCLER\S-1-5-21-761289612-1401638778-1328841865-1006\Dc2\MSNFix\03032008_18452979.zip­/backup/Yazzle1560OinUninstaller.exe -> Not-A-Virus.Adware.PurityScan : Nettoyé.

    Et ça, ça traine dans la poubelle et c'est un Malware. (Pense à vider ta poubelle)

    Chaque fois que tu télécharge quelque chose , clique droit dessus et scan avec Antivir et AVG Anti-spyware.

    S'ils trouvent quelque chose, impitoyablement poubelle.
    0
  14. gigi
     
    voici le rapport antivir - c est important si au debut j ai mis en quarantaine quand il trouvait quelque chose au lieu de faire delete ?????

    AntiVir PersonalEdition Classic
    Report file date: mardi 4 mars 2008 20:34

    Scanning for 1132684 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: NEMEROD

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 19:21:33
    ANTIVIR2.VDF : 7.0.2.181 1993728 Bytes 24/02/2008 19:21:33
    ANTIVIR3.VDF : 7.0.2.231 167424 Bytes 04/03/2008 19:21:33
    AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 04/03/2008 19:21:34
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 04/03/2008 19:21:35
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: mardi 4 mars 2008 20:34

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'PMSHost.exe' - '1' Module(s) have been scanned
    Scan process 'WindowsSearchIndexer.exe' - '1' Module(s) have been scanned
    Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
    Scan process 'FINDFAST.EXE' - '1' Module(s) have been scanned
    Scan process 'OSA.EXE' - '1' Module(s) have been scanned
    Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
    Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
    Scan process 'dslmon.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'EPGSPO~2.EXE' - '1' Module(s) have been scanned
    Scan process 'guard.exe' - '0' Module(s) have been scanned
    Scan process 'QuickAccess.exe' - '1' Module(s) have been scanned
    Scan process 'avgas.exe' - '1' Module(s) have been scanned
    Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'E_FATIABE.EXE' - '1' Module(s) have been scanned
    Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
    Scan process 'PRISMSTA.exe' - '1' Module(s) have been scanned
    Scan process 'remoterm.exe' - '1' Module(s) have been scanned
    Scan process 'PMC.Service.Main.exe' - '1' Module(s) have been scanned
    Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
    Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    47 processes with 47 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [NOTE] No virus was found!
    Master boot sector HD1
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015
    Master boot sector HD2
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015
    Master boot sector HD3
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015
    Master boot sector HD4
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015
    Master boot sector HD5
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '34' files ).

    Starting the file scan:

    Begin scan in 'C:\' <420076>
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Program Files\eMule\Incoming\Norton 2008 Anti virus suite KEY-GEN.zip
    [0] Archive type: ZIP
    --> Norton 2008 Anti virus suite KEY-GEN.exe
    [DETECTION] Contains detection pattern of the worm WORM/Rbot.1276928.1
    [INFO] The file was moved to '483fa677.qua'!
    C:\System Volume Information\_restore{254654D6-6586-4EB1-8C76-5255D53F88EA}\RP738\A0160499.exe
    [DETECTION] Contains detection pattern of the worm WORM/Rbot.1276928.1
    [INFO] The file was moved to '47fea7ed.qua'!
    C:\System Volume Information\_restore{254654D6-6586-4EB1-8C76-5255D53F88EA}\RP738\A0160500.exe
    [DETECTION] Contains detection pattern of the dropper DR/PurityScan.GP.1
    [INFO] The file was moved to '47fea7f0.qua'!
    C:\System Volume Information\_restore{254654D6-6586-4EB1-8C76-5255D53F88EA}\RP740\A0160541.exe
    [DETECTION] Is the Trojan horse TR/Matcash.DLN
    [INFO] The file was moved to '47fea7f7.qua'!
    C:\WINDOWS\system32\eygfih.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!
    C:\WINDOWS\system32\ggzwqp.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!
    C:\WINDOWS\system32\hhjiie.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!
    C:\WINDOWS\system32\pthypy.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!
    C:\WINDOWS\system32\sqgzbm.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was deleted!

    End of the scan: mardi 4 mars 2008 21:01
    Used time: 27:23 min

    The scan has been done completely.

    3999 Scanning directories
    214347 Files were scanned
    9 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    5 files were deleted
    0 files were repaired
    4 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    214338 Files not concerned
    6912 Archives were scanned
    3 Warnings
    10 Notes
    0
  15. gigi
     
    maintenant voila le rapport HitjackThis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:05:35, on 04/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\ATI-CPanel\atiptaxx.exe
    C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
    C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
    C:\WINDOWS\system32\PRISMSTA.EXE
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
    c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
    O4 - HKLM\..\Run: [PRISMSTA.EXE] PRISMSTA.EXE START
    O4 - HKLM\..\Run: [adiras] adiras.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [EPSON Stylus D88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB001" /M "Stylus D88"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Pinnacle Systems tvtv Spooler (EpgSpooler) - - c:\progra~1\pinnacle\mediac~1\epgspo~2.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
    0
  16. gigi
     
    Je te remercie beaucoup pour ton aide mais je crois que pour nous deux c est assez pour ce soir.
    J'ai honte de t'avoir tenu toute la journée et j'imagine que si ca n'a pas été facile pour moi de comprendre tout ce que tu voulais que je fasse, ca a dû être difficile pour toi de me faire arriver a tout ce que tu me demandais. Encore une fois mille mercis - Bonne soirée et a demain pour la finale j'espère.
    0
  17. gigi
     
    He bien voila je viens de finir ce que tu m'avais dit de faire , c'est a dire le point de restauration - Tout est OK
    Je te remercie encore beaucoup - Bonne journée -
    0
Précédent
  • 1
  • 2
  • 3