Probleme de pc. virus probable

latouffe -  
 Utilisateur anonyme -
Bonjour,
J'ai un probleme avec mon PC :Windows XP. Lent et incohérent.J'ai scanné, mais rien ni change. je vous envoie
le rapport hijack. merci de m'expliquer. Je rame dans ce domaine.
A voir également:

23 réponses

Utilisateur anonyme
 
Salut

Il est ou le rapport ?
0
latouffe
 
Bonjour,

Je n'ai pas posté le rapport, parce que je ne sais pas le poster su le site. J'ai le rapport hijackthis. j'ai sélectionné,

copié, collé.Il faudrait m'expliquer pas à pas.

Merci pour votre aide
0
Utilisateur anonyme
 
Re , eh bien tu le colle la ou tu écrit.

C'est simplement du texte ;)

A+
0
latouffe
 
je vous joins le rapport. merci
0
latouffe
 
je te joins le rapport ;je ne suis pas certain que mon précédent message soit bien parti. merci
0
Utilisateur anonyme
 
Je n'ai rien recu.
...

On va faire différemment :

→ Télécharge HJT

Place le dans ' C:\programmes\ ' Une fois cela fait , merci de renommer l'icône ( clique droit > renommer )' Hijackthis.exe 'située dans le dossier dans C:\ , en ' HJT.exe ' <<<<<<<<< Important !!! <<<<<<<

Le chemin d'accés du programme doit être ressemblant à celui-ci : C:\Programme\Trend Micro\Hijackthis\HJT.exe

Ne pas renommer l'icône du raccourci sur le bureau bien entendu ...

→ Puis lance-le et choisi l'option '' do a system scan and save a logfile '' et poste moi le rapport ( qui apparait sur le bloc-note )

Tuto si tu n'y arrive pas : http://pageperso.aol.fr/balltrap34/demohijack.htm

A+
0
latouffe
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:04:00, on 22/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ADSL\StarModem ADSL USB MODEM\dslmon.exe
C:\Documents and Settings\james\Bureau\SetPoint\SetPoint.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PagoBar - {0A4F47F9-E276-4AE4-83E5-C7D9E476883A} - C:\PROGRA~1\PagoBar\PagoBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [9xadiras] 9xadiras.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
0
Utilisateur anonyme
 
Re , fait ceci :

Va sur ce site , /!\ Internet Explorer obligatoire /!\ , Clique sur ' J'accepte ' , Installe les ActiveX si necessaire ,et vérifie si ils sont bien configurés Clique sur ' installer ' puis ' click here to scan '( ou : cliquez ici pour scanner ).
Et poste moi le rapport.

a+
0
latouffe
 
je suis sur I.E, puis sur le site indiqué; j'ai cliqué sur : j'accepte. réponse: impossible de scanner, passez par un autre lien

et là sur une page où je ne peux cliquer sur rien... tout en anglais
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
 
Re , ah merde.

Lance AVG Anti-Spyware

Clique sur le bouton Analyse (de la barre d'outils)

fais dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

Puis sur l'onglet Paramètres
sous "Comment réagir", clique sur Actions recommandées. Sélectionne Quarantaine.

Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

A la fin du scan, choisis l'option 3

"Appliquer toutes les actions " en bas.

Clique sur "Enregistrer le rapport".

Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

Poste le moi.

A+
0
latouffe
 
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 22:39:56 22/03/2008

+ Résultat de l'analyse:



HKU\S-1-5-21-502582692-2177282731-3641348132-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Ignoré.
HKU\S-1-5-21-502582692-2177282731-3641348132-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Ignoré.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Ignoré.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{9d635a36-6b3c-4146-8625-f3aaf507bbf8} -> Adware.RogueSuspect : Ignoré.
:mozilla.152:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.153:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.154:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.155:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.156:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.157:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.159:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.160:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Ignoré.
:mozilla.186:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\james\Cookies\james@adtech[1].txt -> TrackingCookie.Adtech : Ignoré.
:mozilla.257:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.
:mozilla.258:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.
:mozilla.259:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.
:mozilla.260:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.
:mozilla.167:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adviva : Ignoré.
:mozilla.196:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Atdmt : Ignoré.
:mozilla.24:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\james\Cookies\james@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
:mozilla.676:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignoré.
:mozilla.495:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Clickzs : Ignoré.
:mozilla.66:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Doubleclick : Ignoré.
:mozilla.67:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Estat : Ignoré.
:mozilla.795:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.796:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.797:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.798:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.799:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.800:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
:mozilla.183:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignoré.
:mozilla.184:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignoré.
:mozilla.195:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.
C:\Documents and Settings\james\Cookies\james@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Ignoré.
:mozilla.204:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
:mozilla.205:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
:mozilla.206:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
:mozilla.75:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.76:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.77:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.78:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.79:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.80:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.81:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
:mozilla.158:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
:mozilla.163:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
:mozilla.357:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Toplist : Ignoré.
:mozilla.119:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
:mozilla.120:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
:mozilla.121:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
:mozilla.122:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
:mozilla.123:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
:mozilla.230:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.231:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.232:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.233:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.88:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.89:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.90:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.92:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.95:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\james\Cookies\james@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
:mozilla.51:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignoré.
C:\Documents and Settings\james\Cookies\james@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Ignoré.


Fin du rapport

je t'envois ce rapport. merci por la suite
0
Utilisateur anonyme
 
Recommence il a tout ignoré.

fait ceci :
Puis sur l'onglet Paramètres
sous "Comment réagir", clique sur Actions recommandées. Sélectionne Quarantaine.


A+
0
latouffe
 
je te r---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 22:34:33 23/03/2008

+ Résultat de l'analyse:



HKU\S-1-5-21-502582692-2177282731-3641348132-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-502582692-2177282731-3641348132-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.142:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.143:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.144:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.145:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.146:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.147:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.149:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.150:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
C:\Documents and Settings\james\Cookies\james@adrevolver[2].txt -> TrackingCookie.Adrevolver : Nettoyé.
C:\Documents and Settings\james\Cookies\james@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.175:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
C:\Documents and Settings\james\Cookies\james@adtech[1].txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.244:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.245:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.246:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.247:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\james\Cookies\james@advertising[2].txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.157:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
C:\Documents and Settings\james\Cookies\james@adviva[2].txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.185:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\james\Cookies\james@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.37:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\james\Cookies\james@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.661:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Burstbeacon : Nettoyé.
:mozilla.480:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Clickzs : Nettoyé.
:mozilla.59:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\james\Cookies\james@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.60:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\james\Cookies\james@fastclick[2].txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.780:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.781:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.782:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.172:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.173:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.184:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\james\Cookies\james@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.193:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.194:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.195:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\james\Cookies\james@overture[1].txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.65:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.66:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.67:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.68:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.69:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.70:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.71:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.148:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.153:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\james\Cookies\james@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.109:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.110:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.111:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.112:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.113:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\james\Cookies\james@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.217:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.218:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.219:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.220:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.78:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.79:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.80:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.82:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.85:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\james\Cookies\james@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.47:C:\Documents and Settings\james\Application Data\Mozilla\Firefox\Profiles\83rdmgox.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
C:\Documents and Settings\james\Cookies\james@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Nettoyé.


Fin du rapport

envois une analyse
0
Utilisateur anonyme
 
Re ,

Reposte un rapport Hijackthis stp.

A+
0
latouffe
 
Voici
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:59:40, on 23/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ADSL\StarModem ADSL USB MODEM\dslmon.exe
C:\Documents and Settings\james\Bureau\SetPoint\SetPoint.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PagoBar - {0A4F47F9-E276-4AE4-83E5-C7D9E476883A} - C:\PROGRA~1\PagoBar\PagoBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [9xadiras] 9xadiras.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O17 - HKLM\System\CS1\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O22 - SharedTaskScheduler: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
0
Utilisateur anonyme
 
Re !

Tu habites en Italie ?

*******************************************************

Ta version d'Adobe n'est pas à jour , désinstalle ta version actuelle en passant par ' ajout et supréssion de programmes '

Puis télécharge la dernière , via ce site --> https://get2.adobe.com/reader/otherversions/

Bulletin de sécurité sur les versions Adobe 7.0.8 et antérieures :

https://www.adobe.com/support/security/bulletins/apsb07-01.html

https://get2.adobe.com/reader/otherversions/

**************************************************
→ Relance hijackthis , Choisis ' Do a system scan ' Et fixe ces lignes : ( coche la case à leurs gauches > ' fixchecked ')

O4 - Global Startup: DSLMON.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O22 - SharedTaskScheduler: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - (no file)

**********************************************

Désinstalle Norton :

http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

Et télécharge Antivir ( PersonnalEdition Classic) → ici

Tuto Installation + configuration Antivir → https://www.malekal.com/avira-free-security-antivirus-gratuit/

Tuto Installation : → https://www.astucesinternet.com/modules/news/article.php?storyid=253

Pour le rendre encore plus discret....

******************************************

Télécharge le pare-feu ZoneAlarm Lit bien tout l'article pour éviter les surprises.

Des soucis avec ?

***************************************

→ Télécharge CleanUp452 ( Primary download site ... )

→ Lance-le et choisi l'option ' cleanup! '

Poste le rapport.

Tutorial: http://pageperso.aol.fr/balltrap34/democleanup.htm ( merci à balltrap34 )

************************************

→ Télécharge clean : http://www.malekal.com/download/clean.zip

→ Dézippe-le ( clique droit , extraire tout)

→ Lance clean.cmd ( ou clean ), Choisi l'option 1 et poste moi le rapport.

(- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

Note : Tu auras peut-être un message qui t'invitera a uploader un fichier , fait-le dès que tu pourras.

*********************************

3 rapports.

_Cleanup
_Clean
_Hijackthis


A poster dans l'ordre.

A+
0
latouffe
 
Voici le 1er rapport sur les trois demandés.
En effet je réside en Italie. Dans un petit village où je suis bien isolé(informatiquement parlant) je n'ai pas d'échanges.

Heureusement qu'il existe cette communauté et des gens comme toi pour aider les modestes internautes. Merci

CleanUp! started on 03/24/08 09:56:03.
...
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\I31FHGHA\unlimited[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\I31FHGHA\UT[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\I31FHGHA\WindowsLive[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\I31FHGHA\yui_2.3.1_1[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\0000000001_000000000000000301318[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\0000000001_000000000000000319645[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\0000000001_000000000000000353126[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\10356336-4[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\1431867162@Top,Middle,TopRight[1] - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\35373037636537343437653535326330[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\5[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\61046683[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\70x50cetelem[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\931x100_mobile[1].swf - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ADSAdClient31[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ADSAdClient31[2].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ADSAdClient31[3].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ADSAdClient31[4].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\answers_favicon[1].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\antivir-parametrage-002[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\Antivir-parametrage-menu-001[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\arrow[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\arrow[2].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ATT00083[1].swf - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\b3[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\back_onglets[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\back_suite02[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\back_tabs[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\back_titre[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\bcr_2.0.4[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\bhp002[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\bhp006[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\bhp010[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\botSx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\btnMenu01[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\btn_search_01[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\BurstingInteractionsPipe[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\button_bg[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\CAAWDSBC.HTM - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\CAJERGD6 - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\calciatori2_2[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\clear[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\clear[2].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\easte1[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\faviconCA0E1LBG.ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\faviconCAYE6QIL.ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[10].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[11].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[1].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[2].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[3].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[4].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[5].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[6].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[7].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[8].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\favicon[9].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\flechebas[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\fotDx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\freccette_Big[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\fr_yahoo_com[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\gif_totocalcio_tris[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\giocoResponsabile[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\header[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\hit[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\homeScommesse[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\icoLogout[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\InboxLight[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\i_help[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\i_yellowshield[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\LayoutCommon[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\Light[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\logoAmsBkgnd[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\logoAmsPart2[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\logo[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\manifestazioniDwr[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\midDx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\midSx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\midSx[2].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\mpoko8[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\never_lose[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\nissa[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\pcbackedup_gw_logo[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\pic_empty[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\pic_rss[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\plx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ReadMessageLight[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ReadMessageLight[2].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ReadMessageLight[3].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ReadMessageLight[4].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\Request[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\show_ads[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\sprite_forum[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\template_css[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\TFSMflashobject[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\thala7[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\ToolbarBG[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\topCen[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\topDx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\topSx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\touch[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\tracker[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\transp[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\tryitfree_gw_logo[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\utbkgnd[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\util[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\v53[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\wbk194.tmp - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\P0GV4BDA\zlsSetup_70_462_000_fr[1].exe - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\10356341-3[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\1149046468@Position4!Position4[1] - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\60996034[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\61045671[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\actions_06[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[2].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[3].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[4].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[5].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ADSAdClient31[6].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ads[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\advertisement[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\affich-5553728-probleme-de-pc-virus-probable[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\affich-5553728-probleme-de-pc-virus-probable[2].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ajout[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\b2[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\back_ccm_ht[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\back_suite01[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\back_tab_off6[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\back_titre[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bannerSMSetteMezzo[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bannerSM_FortunaGira[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bannerSM_Miliardario[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bgMenu[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bhp003[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bhp007[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\bnt_search[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\botSx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\btnApriContoTop[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\calcio_portiere_S[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\carrelloDwr[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\doveGiocare[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ebay2[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\emailButton[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\empty[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\engine[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\faviconCA0J7IGQ.ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[10].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[11].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[1].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[2].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[3].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[4].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[5].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[6].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[7].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[8].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\favicon[9].ico - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\flag_es[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\flag_fr[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\forum[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\header_short[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\homeBetterDwr[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\home_better[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\icc_left1[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\icons_1.1[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ilede1[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\InboxLight[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\indent1[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\intermerche350x200[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\jewel_24_hover[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\jquery-1.2.3.pack[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\LayoutInbox_12.4.0078.0228[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\LayoutItemList[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\lmatica_testata[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\logo_box_gvinci[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\lottomaticard[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\lunet1[1].jpg - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\midDx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\midSx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\paic2[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\pic_02[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\pic_next[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\poivre[1].swf - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\prof[1].xml - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\p[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ReadMessageLight[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ReadMessageLight[1].js - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\rssico[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\scommesse[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sc_rest[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sempliceVeloce[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sfondoIcone[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sfondo_banner[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\spacerVerdeScommesse[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sprite_charte[1].png - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\sp_3[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\supporto[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\ThemeCommon_12.4.0078.0228[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\titGiocoOnLine[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\topCen[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\topDx[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\trans1x1[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\trans1[1].gif - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\WEBWinLive1036[1].css - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\WLLogin_JS[1].htm - deleted
C:\Documents and Settings\james\Local Settings\Temporary Internet Files\Content.IE5\VO82Q4NW\yad5[1].js - deleted
C:\Documents and Settings\Default User\Cookies\index.dat - deleted
C:\Documents and Settings\Default User\locals~1\tempor~1\Content.IE5\index.dat - deleted
C:\Documents and Settings\Default User\Cookies\index.dat - deleted
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat - deleted
Emptied Recycle Bin on drive C:
'Run MRU' list - removed from the registry.
'Doc Find Spec MRU' list - removed from the registry.
'FindComputerMRU' list - removed from the registry.
'ComputerNameMRU' list - removed from the registry.
'ContainingTextMRU' list - removed from the registry.
'FilesNamedMRU' list - removed from the registry.
Search Assistant MRU list - removed from the registry.
Explorer Open/Save MRU list - removed from the registry.
Explorer Last Visited MRU list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
Windows Media Player Recent File List - removed from the registry.
WinZip Extract MRU list - removed from the registry.
WinZip File MRU list - removed from the registry.
CleanUp! 4.5.2 recovered 368.0 MB of disk space from 3664 files.
CleanUp! finished on 03/24/08 09:56:32.
0
Utilisateur anonyme
 
De rien =)

Et hop 370 mo de gagné ;)

Passe à clean maintenant.

A+
0
latouffe
 
Re,

J'ai repris ta procédure. Jesuis sur Clean que j'ai chargé et dézipé. Problème! quand je lance clean: fenetre s'ouvre

sur des icones bleues: "cherche", clean, del2, del3, etc.

l'option 1, c'est quoi? c'est " cherche" ?
0
Utilisateur anonyme
 
Re ,

C'est marqué pourtant ...

clean.cmd ( ou clean tout seul )

a+
0
latouffe
 
Dans C/ sur clean. puis sur icone (roue); fichier ouvert>> exécuter>> fenetre noire et demande faire choix:

1. rechercher 2. nettoyer 3. quitter. Je mets en surbrillance 1. mais rien ne se passe. rien à cliquer??
0
Utilisateur anonyme
 
?

tu tapes 1 puis [entrée]

A+
0
latouffe
 
Je suis nul !
24/03/2008 a 20:30:30,93

*** Recherche des fichiers dans C:

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\InternetGameBox\" FOUND
*** Fin du rapport !
0
Utilisateur anonyme
 
→ Redémarre en MSE

Autre tutorials pour MSE:

https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
http://www.coupdepoucepc.com/modules/news/article.php?storyid=253

→ Re-lance clean -> Choisis l'option 2

---Clean va travailler.---

→ Un rapport Va etre généré , poste le moi ;)

( Le rapport est aussi sauvegardé dans C:\Rapport_clean.txt )

+ un autre rapport hijackthis.

a+
0
latouffe
 
clean relancé e MSE: 24/03/2008 a 21:14:59,45

*** Recherche des fichiers dans C:

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\InternetGameBox\" FOUND
*** Fin du rapport !

Et dernier rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:54, on 24/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: PagoBar - {0A4F47F9-E276-4AE4-83E5-C7D9E476883A} - C:\PROGRA~1\PagoBar\PagoBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [9xadiras] 9xadiras.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O17 - HKLM\System\CS1\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
Utilisateur anonyme
 
Clean option2 stp pas 1.
Recommence
A+
0
latouffe
 
En MSE j'ai cliqué sur 2 ( nettoyage)

Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 24/03/2008 a 21:46:03,76

Microsoft Windows XP [version 5.1.2600]

*** Suppression des fichiers dans C:

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32

*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\InternetGameBox\"

*** Suppression des clefs du registre effectuee..
*** Fin du rapport !

Je t'ai refais hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:21, on 24/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: PagoBar - {0A4F47F9-E276-4AE4-83E5-C7D9E476883A} - C:\PROGRA~1\PagoBar\PagoBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [9xadiras] 9xadiras.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O17 - HKLM\System\CS1\Services\Tcpip\..\{3E4E9FDC-67A5-45FA-9AA4-50D7CF1507CB}: NameServer = 85.37.17.55 85.38.28.93
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
Utilisateur anonyme
 
Re ahh voila =)

bon bon bon :

→ Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

→ Double clique sur ToolsCleaner2.exe >
→ Clique sur .Recherche
→ puis sur Suppression quand la liste est trouvée.
→ Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

Tuto : http://www.commentcamarche.net/faq/sujet 8341 toolscleaner suppression des fix de force brute ( merci espion3004 )

ton pc est-t'il toujours aussi lent ?
a+
0
latouffe
 
Voici le rapport. mon PC est moins lent.

-->- Recherche:

C:\Clean.zip: trouvé !
C:\HijackThis: trouvé !
C:\clean\clean\tar.exe: trouvé !
C:\clean\clean\remove.reg: trouvé !
C:\clean\clean\pskill.exe: trouvé !
C:\clean\clean\LFiles.exe: trouvé !
C:\clean\clean\gzip.exe: trouvé !
C:\clean\clean\delsiri.cmd: trouvé !
C:\clean\clean\delr.cmd: trouvé !
C:\clean\clean\del3.cmd: trouvé !
C:\clean\clean\del2.cmd: trouvé !
C:\clean\clean\clean.cmd: trouvé !
C:\clean\clean\cherche.cmd: trouvé !
C:\Documents and Settings\james\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\james\Bureau\HJTInstall.exe: trouvé !
C:\Documents and Settings\james\Local Settings\Temp\Répertoire temporaire 1 pour clean.zip\clean\clean.cmd: trouvé !
C:\Documents and Settings\james\Local Settings\Temp\Répertoire temporaire 2 pour clean.zip\clean\clean.cmd: trouvé !
C:\Documents and Settings\james\Mes documents\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\cherche.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\cherche.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\cherche.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\cherche.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\cherche.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\tar.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\remove.reg: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\pskill.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\LFiles.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\gzip.exe: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\delsiri.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\delr.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\del3.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\del2.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\clean.cmd: trouvé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\cherche.cmd: trouvé !

---------------------------------
-->- Suppression:

C:\Clean.zip: supprimé !
C:\clean\clean\tar.exe: supprimé !
C:\clean\clean\remove.reg: supprimé !
C:\clean\clean\pskill.exe: supprimé !
C:\clean\clean\LFiles.exe: supprimé !
C:\clean\clean\gzip.exe: supprimé !
C:\clean\clean\delsiri.cmd: supprimé !
C:\clean\clean\delr.cmd: supprimé !
C:\clean\clean\del3.cmd: supprimé !
C:\clean\clean\del2.cmd: supprimé !
C:\clean\clean\clean.cmd: supprimé !
C:\clean\clean\cherche.cmd: supprimé !
C:\Documents and Settings\james\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\james\Bureau\HJTInstall.exe: supprimé !
C:\Documents and Settings\james\Local Settings\Temp\Répertoire temporaire 1 pour clean.zip\clean\clean.cmd: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\james\Local Settings\Temp\Répertoire temporaire 2 pour clean.zip\clean\clean.cmd: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\james\Mes documents\HijackThis.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc101\clean\cherche.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\cherche.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc96\clean\cherche.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc97\clean\cherche.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc98\clean\cherche.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\tar.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\remove.reg: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\pskill.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\LFiles.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\gzip.exe: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\delsiri.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\delr.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\del3.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\del2.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\clean.cmd: supprimé !
C:\RECYCLER\S-1-5-21-502582692-2177282731-3641348132-1006\Dc99\cherche.cmd: supprimé !
C:\HijackThis: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !

Sauvegarde du registre crée !
0
Utilisateur anonyme
 
Re =)

Maintenant que ton PC n'est plus infecté, désactive ta "Restauration du système" puis réactive la, ce qui créer un point de restauration sain...

Désactivation :
Clique droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > coche la case "Désactiver la Restauration du système sur tous les lecteurs"
> Applique patiente jusqu’à ce que cela soit marqué "désactivé" puis Ok.

Activation :
Suivre le même chemin ; décoche la case "Désactiver la Restauration du système sur tous les lecteurs"
> Applique attends que cela soit à nouveau sur "surveillance" puis Ok. Redémarre l'ordinateur.

+++
0
latouffe
 
Bonsoir,
j'ai fait la manip. je voudrais savoir ce que je dois conserver. tout ce que tu m'as demandé de télécharger :

AVIR, AVG, CLEAN, ZONEALARM etc... NORTON que j'avais jusqu'à maintenant, je laisse tomber? merci de

me dire.
0