Probleme avec fenetre CID
madmax91
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Voila comme beaucoup d'autre j'ai des problèmes de fenêtres publicitaires nommées CID , j'en avais d'autres avant qu j'ai réussi a éradiquer je ne sait plus trop par quels moyens que j' ai trouver sur un autre post de ce site.
En ce qui concerne les fenêtres CID j'ai supprimer le sponsor de msn avec windows en mode sans échec mais elles reviennent toujours et aucune trace d'instalation nommée "CIDhelp" ou autre
quelle est la procédure a suivre avec les histoires de rapports désolé de reposer cette question mais cela commence a m'énerver ces fenêtres
merci d'avance
Voila comme beaucoup d'autre j'ai des problèmes de fenêtres publicitaires nommées CID , j'en avais d'autres avant qu j'ai réussi a éradiquer je ne sait plus trop par quels moyens que j' ai trouver sur un autre post de ce site.
En ce qui concerne les fenêtres CID j'ai supprimer le sponsor de msn avec windows en mode sans échec mais elles reviennent toujours et aucune trace d'instalation nommée "CIDhelp" ou autre
quelle est la procédure a suivre avec les histoires de rapports désolé de reposer cette question mais cela commence a m'énerver ces fenêtres
merci d'avance
A voir également:
- Probleme avec fenetre CID
- Fenetre windows - Guide
- Fenêtre hors écran windows 11 - Guide
- Fenetre de navigation privée - Guide
- Mcafee fenetre intempestive - Accueil - Piratage
- Forcer fermeture fenetre windows - Guide
14 réponses
Bonjour,
Télécharge lopS&D.exe sur ton bureau (Clique-droit sur le lien > Enregister la cible du lien sous)
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Désactive ton antivirs au cas où (tu pourras le réactiver après la fin du scan)
Double-clique sur lopSD pour lancer l'installation
Une fois installé, double-clique Lop S&D
Sélectionne la langue en appuyant sur la touche F, puis choisis l'option 1 (Recherche)
Si lopSD te demande de redémarrer accepte et attends la fin du scan.
Copie/colle le contenu du rapport qui se situe à la racine du DD C:\lopR.txt
Ensuite,
Télécharge HijackThis
http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
Installe le à la racine de ton disque dur
Lance HijackThis en double-cliquant sur l'icône HijackThis
Clique sur Do a system Scan only and Save a Logfile
Un rapport sera généré dans le bloc-note (le rapport est également situé ici : C:\hijackthis.log)
Copie/colle le rapport dans ton prochain message.
Télécharge lopS&D.exe sur ton bureau (Clique-droit sur le lien > Enregister la cible du lien sous)
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Désactive ton antivirs au cas où (tu pourras le réactiver après la fin du scan)
Double-clique sur lopSD pour lancer l'installation
Une fois installé, double-clique Lop S&D
Sélectionne la langue en appuyant sur la touche F, puis choisis l'option 1 (Recherche)
Si lopSD te demande de redémarrer accepte et attends la fin du scan.
Copie/colle le contenu du rapport qui se situe à la racine du DD C:\lopR.txt
Ensuite,
Télécharge HijackThis
http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
Installe le à la racine de ton disque dur
Lance HijackThis en double-cliquant sur l'icône HijackThis
Clique sur Do a system Scan only and Save a Logfile
Un rapport sera généré dans le bloc-note (le rapport est également situé ici : C:\hijackthis.log)
Copie/colle le rapport dans ton prochain message.
les voila :
le premier
-----------------------[ Lop S&D 4.2.0-8 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : jort maxime ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 13/05/2008 | 20:37:42,04 ] [ PC : MAXIME-6Z2LZVQM ]
[ MAJ : 11-05-2008 | 18:25 ]
-------------[ Listing des dossiers dans Application Data ]------------
[05/04/2008|15:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[13/05/2008|19:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuneUp Software
[01/05/2008|23:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{A850D4D9-871B-4234-908D-21C457767270}
[01/05/2008|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[05/04/2008|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[05/04/2008|22:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[05/04/2008|15:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/05/2008|11:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
[06/04/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[07/05/2008|13:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[05/04/2008|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[06/04/2008|12:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/04/2008|15:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/05/2008|16:09] C:\DOCUME~1\JORTMA~1\APPLIC~1\Adobe
[01/05/2008|16:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\AdobeUM
[06/04/2008|17:27] C:\DOCUME~1\JORTMA~1\APPLIC~1\Apple Computer
[29/04/2008|11:50] C:\DOCUME~1\JORTMA~1\APPLIC~1\Atari
[05/04/2008|22:31] C:\DOCUME~1\JORTMA~1\APPLIC~1\DAEMON Tools
[05/04/2008|15:15] C:\DOCUME~1\JORTMA~1\APPLIC~1\desktop.ini
[11/05/2008|21:13] C:\DOCUME~1\JORTMA~1\APPLIC~1\dvdcss
[06/04/2008|21:08] C:\DOCUME~1\JORTMA~1\APPLIC~1\ESTSoft
[01/05/2008|11:12] C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
[05/04/2008|14:26] C:\DOCUME~1\JORTMA~1\APPLIC~1\Identities
[07/05/2008|19:01] C:\DOCUME~1\JORTMA~1\APPLIC~1\LimeWire
[05/04/2008|21:11] C:\DOCUME~1\JORTMA~1\APPLIC~1\Logitech
[05/04/2008|23:35] C:\DOCUME~1\JORTMA~1\APPLIC~1\Macromedia
[12/05/2008|11:02] C:\DOCUME~1\JORTMA~1\APPLIC~1\Microsoft
[05/04/2008|22:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\Mozilla
[26/04/2008|19:59] C:\DOCUME~1\JORTMA~1\APPLIC~1\Sun
[05/04/2008|20:57] C:\DOCUME~1\JORTMA~1\APPLIC~1\TuneUp Software
[06/04/2008|14:56] C:\DOCUME~1\JORTMA~1\APPLIC~1\vlc
[05/04/2008|14:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[05/04/2008|14:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[13/05/2008 19:00][--ah-----] C:\WINDOWS\tasks\AC662DE39185DE33.job
[05/04/2008 22:56][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[13/05/2008 20:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
AC662DE39185DE33.job <--> c:\docume~1\jortma~1\applic~1\gpltitle\cakebrowseclose.exe
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[01/05/2008|16:07] C:\Program Files\Adobe
[05/04/2008|20:20] C:\Program Files\Alwil Software
[05/04/2008|22:56] C:\Program Files\Apple Software Update
[01/05/2008|11:31] C:\Program Files\Atari
[05/04/2008|20:45] C:\Program Files\ATI Technologies
[05/04/2008|20:24] C:\Program Files\AvRack
[01/05/2008|11:32] C:\Program Files\BitComet
[19/04/2008|22:55] C:\Program Files\Call of Duty Game of the Year Edition
[05/04/2008|23:02] C:\Program Files\CCleaner
[05/04/2008|14:20] C:\Program Files\ComPlus Applications
[05/04/2008|22:33] C:\Program Files\DAEMON Tools Lite
[09/04/2008|14:33] C:\Program Files\DOSBox-0.72
[10/05/2008|00:43] C:\Program Files\eMule
[05/04/2008|22:59] C:\Program Files\ESTsoft
[01/05/2008|16:09] C:\Program Files\Fichiers communs
[13/05/2008|19:01] C:\Program Files\GameSpy Arcade
[01/05/2008|11:11] C:\Program Files\gpltitle
[10/05/2008|22:41] C:\Program Files\InstallShield Installation Information
[13/04/2008|02:47] C:\Program Files\Internet Explorer
[05/04/2008|23:04] C:\Program Files\iPod
[05/04/2008|23:04] C:\Program Files\iTunes
[23/04/2008|11:51] C:\Program Files\Java
[12/04/2008|01:47] C:\Program Files\LimeWire
[05/04/2008|20:48] C:\Program Files\Logitech
[05/04/2008|20:28] C:\Program Files\Marvell
[10/04/2008|00:40] C:\Program Files\Messenger
[13/05/2008|20:18] C:\Program Files\Messenger Plus! Live
[05/04/2008|14:23] C:\Program Files\microsoft frontpage
[09/04/2008|18:45] C:\Program Files\Microsoft Office
[05/04/2008|21:07] C:\Program Files\Movie Maker
[13/05/2008|20:35] C:\Program Files\Mozilla Firefox
[09/04/2008|14:57] C:\Program Files\MSECache
[05/04/2008|14:20] C:\Program Files\MSN
[05/04/2008|14:20] C:\Program Files\MSN Gaming Zone
[07/05/2008|15:46] C:\Program Files\Navilog1
[05/04/2008|21:06] C:\Program Files\NetMeeting
[10/04/2008|00:39] C:\Program Files\Outlook Express
[05/04/2008|23:02] C:\Program Files\QuickTime
[05/04/2008|20:21] C:\Program Files\Realtek Sound Manager
[05/04/2008|14:20] C:\Program Files\Services en ligne
[10/05/2008|23:09] C:\Program Files\Sierra
[27/04/2008|15:38] C:\Program Files\SprayR
[01/05/2008|23:38] C:\Program Files\Stardock
[13/05/2008|19:31] C:\Program Files\Steam
[23/04/2008|15:54] C:\Program Files\TmNationsForever
[13/04/2008|01:18] C:\Program Files\TuneUp Utilities 2008
[05/04/2008|14:26] C:\Program Files\Uninstall Information
[05/04/2008|23:00] C:\Program Files\VideoLAN
[06/04/2008|12:03] C:\Program Files\Windows Live
[10/04/2008|00:39] C:\Program Files\Windows Media Player
[09/04/2008|18:44] C:\Program Files\Windows Messaging
[05/04/2008|21:06] C:\Program Files\Windows NT
[05/04/2008|14:20] C:\Program Files\WindowsUpdate
[08/04/2008|23:07] C:\Program Files\WinISO
[05/04/2008|22:13] C:\Program Files\WinRAR
[05/04/2008|14:23] C:\Program Files\xerox
[13/05/2008|19:42] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[01/05/2008|16:09] C:\Program Files\Fichiers communs\Adobe
[05/04/2008|22:56] C:\Program Files\Fichiers communs\Apple
[05/04/2008|20:48] C:\Program Files\Fichiers communs\InstallShield
[12/04/2008|01:45] C:\Program Files\Fichiers communs\Java
[05/04/2008|20:48] C:\Program Files\Fichiers communs\Logitech
[09/04/2008|18:45] C:\Program Files\Fichiers communs\Microsoft Shared
[05/04/2008|14:21] C:\Program Files\Fichiers communs\MSSoap
[05/04/2008|15:15] C:\Program Files\Fichiers communs\ODBC
[29/04/2008|11:49] C:\Program Files\Fichiers communs\PocketSoft
[05/04/2008|14:21] C:\Program Files\Fichiers communs\Services
[05/04/2008|15:15] C:\Program Files\Fichiers communs\SpeechEngines
[10/04/2008|00:39] C:\Program Files\Fichiers communs\System
[06/04/2008|12:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[05/04/2008|22:02] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 38
iexplore.exe ~ [512]
iexplore.exe ~ [1452]
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave\bend creative.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\cakebrowseclose.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\jjcbcznv.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\kindpollatomonce.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\rzyjowjr.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
C:\Program Files\gpltitle
C:\WINDOWS\Tasks\AC662DE39185DE33.job
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"settingsiso"="C:\\DOCUME~1\\JORTMA~1\\APPLIC~1\\gpltitle\\soft bias.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 72 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 20:38:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:231][Doss:6] C:\DOCUME~1\JORTMA~1\LOCALS~1\Temp
/!\ [Fich:84][Doss:0] C:\DOCUME~1\JORTMA~1\Cookies
/!\ [Fich:2589][Doss:8] C:\DOCUME~1\JORTMA~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:39:00,17 ]----------------------
le premier
-----------------------[ Lop S&D 4.2.0-8 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : jort maxime ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 13/05/2008 | 20:37:42,04 ] [ PC : MAXIME-6Z2LZVQM ]
[ MAJ : 11-05-2008 | 18:25 ]
-------------[ Listing des dossiers dans Application Data ]------------
[05/04/2008|15:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[13/05/2008|19:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuneUp Software
[01/05/2008|23:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{A850D4D9-871B-4234-908D-21C457767270}
[01/05/2008|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[05/04/2008|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[05/04/2008|22:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[05/04/2008|15:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/05/2008|11:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
[06/04/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[07/05/2008|13:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[05/04/2008|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[06/04/2008|12:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/04/2008|15:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/05/2008|16:09] C:\DOCUME~1\JORTMA~1\APPLIC~1\Adobe
[01/05/2008|16:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\AdobeUM
[06/04/2008|17:27] C:\DOCUME~1\JORTMA~1\APPLIC~1\Apple Computer
[29/04/2008|11:50] C:\DOCUME~1\JORTMA~1\APPLIC~1\Atari
[05/04/2008|22:31] C:\DOCUME~1\JORTMA~1\APPLIC~1\DAEMON Tools
[05/04/2008|15:15] C:\DOCUME~1\JORTMA~1\APPLIC~1\desktop.ini
[11/05/2008|21:13] C:\DOCUME~1\JORTMA~1\APPLIC~1\dvdcss
[06/04/2008|21:08] C:\DOCUME~1\JORTMA~1\APPLIC~1\ESTSoft
[01/05/2008|11:12] C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
[05/04/2008|14:26] C:\DOCUME~1\JORTMA~1\APPLIC~1\Identities
[07/05/2008|19:01] C:\DOCUME~1\JORTMA~1\APPLIC~1\LimeWire
[05/04/2008|21:11] C:\DOCUME~1\JORTMA~1\APPLIC~1\Logitech
[05/04/2008|23:35] C:\DOCUME~1\JORTMA~1\APPLIC~1\Macromedia
[12/05/2008|11:02] C:\DOCUME~1\JORTMA~1\APPLIC~1\Microsoft
[05/04/2008|22:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\Mozilla
[26/04/2008|19:59] C:\DOCUME~1\JORTMA~1\APPLIC~1\Sun
[05/04/2008|20:57] C:\DOCUME~1\JORTMA~1\APPLIC~1\TuneUp Software
[06/04/2008|14:56] C:\DOCUME~1\JORTMA~1\APPLIC~1\vlc
[05/04/2008|14:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[05/04/2008|14:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[13/05/2008 19:00][--ah-----] C:\WINDOWS\tasks\AC662DE39185DE33.job
[05/04/2008 22:56][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[13/05/2008 20:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
AC662DE39185DE33.job <--> c:\docume~1\jortma~1\applic~1\gpltitle\cakebrowseclose.exe
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[01/05/2008|16:07] C:\Program Files\Adobe
[05/04/2008|20:20] C:\Program Files\Alwil Software
[05/04/2008|22:56] C:\Program Files\Apple Software Update
[01/05/2008|11:31] C:\Program Files\Atari
[05/04/2008|20:45] C:\Program Files\ATI Technologies
[05/04/2008|20:24] C:\Program Files\AvRack
[01/05/2008|11:32] C:\Program Files\BitComet
[19/04/2008|22:55] C:\Program Files\Call of Duty Game of the Year Edition
[05/04/2008|23:02] C:\Program Files\CCleaner
[05/04/2008|14:20] C:\Program Files\ComPlus Applications
[05/04/2008|22:33] C:\Program Files\DAEMON Tools Lite
[09/04/2008|14:33] C:\Program Files\DOSBox-0.72
[10/05/2008|00:43] C:\Program Files\eMule
[05/04/2008|22:59] C:\Program Files\ESTsoft
[01/05/2008|16:09] C:\Program Files\Fichiers communs
[13/05/2008|19:01] C:\Program Files\GameSpy Arcade
[01/05/2008|11:11] C:\Program Files\gpltitle
[10/05/2008|22:41] C:\Program Files\InstallShield Installation Information
[13/04/2008|02:47] C:\Program Files\Internet Explorer
[05/04/2008|23:04] C:\Program Files\iPod
[05/04/2008|23:04] C:\Program Files\iTunes
[23/04/2008|11:51] C:\Program Files\Java
[12/04/2008|01:47] C:\Program Files\LimeWire
[05/04/2008|20:48] C:\Program Files\Logitech
[05/04/2008|20:28] C:\Program Files\Marvell
[10/04/2008|00:40] C:\Program Files\Messenger
[13/05/2008|20:18] C:\Program Files\Messenger Plus! Live
[05/04/2008|14:23] C:\Program Files\microsoft frontpage
[09/04/2008|18:45] C:\Program Files\Microsoft Office
[05/04/2008|21:07] C:\Program Files\Movie Maker
[13/05/2008|20:35] C:\Program Files\Mozilla Firefox
[09/04/2008|14:57] C:\Program Files\MSECache
[05/04/2008|14:20] C:\Program Files\MSN
[05/04/2008|14:20] C:\Program Files\MSN Gaming Zone
[07/05/2008|15:46] C:\Program Files\Navilog1
[05/04/2008|21:06] C:\Program Files\NetMeeting
[10/04/2008|00:39] C:\Program Files\Outlook Express
[05/04/2008|23:02] C:\Program Files\QuickTime
[05/04/2008|20:21] C:\Program Files\Realtek Sound Manager
[05/04/2008|14:20] C:\Program Files\Services en ligne
[10/05/2008|23:09] C:\Program Files\Sierra
[27/04/2008|15:38] C:\Program Files\SprayR
[01/05/2008|23:38] C:\Program Files\Stardock
[13/05/2008|19:31] C:\Program Files\Steam
[23/04/2008|15:54] C:\Program Files\TmNationsForever
[13/04/2008|01:18] C:\Program Files\TuneUp Utilities 2008
[05/04/2008|14:26] C:\Program Files\Uninstall Information
[05/04/2008|23:00] C:\Program Files\VideoLAN
[06/04/2008|12:03] C:\Program Files\Windows Live
[10/04/2008|00:39] C:\Program Files\Windows Media Player
[09/04/2008|18:44] C:\Program Files\Windows Messaging
[05/04/2008|21:06] C:\Program Files\Windows NT
[05/04/2008|14:20] C:\Program Files\WindowsUpdate
[08/04/2008|23:07] C:\Program Files\WinISO
[05/04/2008|22:13] C:\Program Files\WinRAR
[05/04/2008|14:23] C:\Program Files\xerox
[13/05/2008|19:42] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[01/05/2008|16:09] C:\Program Files\Fichiers communs\Adobe
[05/04/2008|22:56] C:\Program Files\Fichiers communs\Apple
[05/04/2008|20:48] C:\Program Files\Fichiers communs\InstallShield
[12/04/2008|01:45] C:\Program Files\Fichiers communs\Java
[05/04/2008|20:48] C:\Program Files\Fichiers communs\Logitech
[09/04/2008|18:45] C:\Program Files\Fichiers communs\Microsoft Shared
[05/04/2008|14:21] C:\Program Files\Fichiers communs\MSSoap
[05/04/2008|15:15] C:\Program Files\Fichiers communs\ODBC
[29/04/2008|11:49] C:\Program Files\Fichiers communs\PocketSoft
[05/04/2008|14:21] C:\Program Files\Fichiers communs\Services
[05/04/2008|15:15] C:\Program Files\Fichiers communs\SpeechEngines
[10/04/2008|00:39] C:\Program Files\Fichiers communs\System
[06/04/2008|12:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[05/04/2008|22:02] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 38
iexplore.exe ~ [512]
iexplore.exe ~ [1452]
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave\bend creative.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\cakebrowseclose.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\jjcbcznv.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\kindpollatomonce.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\rzyjowjr.exe
C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
C:\Program Files\gpltitle
C:\WINDOWS\Tasks\AC662DE39185DE33.job
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"settingsiso"="C:\\DOCUME~1\\JORTMA~1\\APPLIC~1\\gpltitle\\soft bias.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD
-> 72 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 20:38:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:231][Doss:6] C:\DOCUME~1\JORTMA~1\LOCALS~1\Temp
/!\ [Fich:84][Doss:0] C:\DOCUME~1\JORTMA~1\Cookies
/!\ [Fich:2589][Doss:8] C:\DOCUME~1\JORTMA~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:39:00,17 ]----------------------
et le rapport de hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:44:33, on 13/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [settingsiso] C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:44:33, on 13/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [settingsiso] C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
bonjour
va dans ajout & supprimer programmes !
et vois si tu vois sponsor Cid, et tout ce que tu peut voir comme CID ! oui supprime !
et fait un MSNfix ,
ça devrait résoudre ton problème !
http://www.infos-du-net.com/telecharger/MSNFix,0301-11762.html
va dans ajout & supprimer programmes !
et vois si tu vois sponsor Cid, et tout ce que tu peut voir comme CID ! oui supprime !
et fait un MSNfix ,
ça devrait résoudre ton problème !
http://www.infos-du-net.com/telecharger/MSNFix,0301-11762.html
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
D'abord relance LOPS&D et choisis l'option 2.
Il y a pas mal de choses à supprimer, notamment le fichier .job etc...
Faisons les étapes dans l'ordre. ;)
Il y a pas mal de choses à supprimer, notamment le fichier .job etc...
Faisons les étapes dans l'ordre. ;)
voici le rapord de LOPS&D
apré avoir fait loption 2
-----------------------[ Lop S&D 4.2.0-8 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : jort maxime ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 13/05/2008 | 20:53:17,59 ] [ PC : MAXIME-6Z2LZVQM ]
[ MAJ : 11-05-2008 | 18:25 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave\bend creative.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\cakebrowseclose.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\jjcbcznv.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\kindpollatomonce.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\rzyjowjr.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
Supprimé! - C:\WINDOWS\Tasks\AC662DE39185DE33.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
Supprimé! - C:\Program Files\gpltitle
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[05/04/2008|15:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[13/05/2008|19:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuneUp Software
[01/05/2008|23:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{A850D4D9-871B-4234-908D-21C457767270}
[01/05/2008|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[05/04/2008|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[05/04/2008|22:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[05/04/2008|15:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[06/04/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[07/05/2008|13:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[05/04/2008|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[06/04/2008|12:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/04/2008|15:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/05/2008|16:09] C:\DOCUME~1\JORTMA~1\APPLIC~1\Adobe
[01/05/2008|16:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\AdobeUM
[06/04/2008|17:27] C:\DOCUME~1\JORTMA~1\APPLIC~1\Apple Computer
[29/04/2008|11:50] C:\DOCUME~1\JORTMA~1\APPLIC~1\Atari
[05/04/2008|22:31] C:\DOCUME~1\JORTMA~1\APPLIC~1\DAEMON Tools
[05/04/2008|15:15] C:\DOCUME~1\JORTMA~1\APPLIC~1\desktop.ini
[11/05/2008|21:13] C:\DOCUME~1\JORTMA~1\APPLIC~1\dvdcss
[06/04/2008|21:08] C:\DOCUME~1\JORTMA~1\APPLIC~1\ESTSoft
[05/04/2008|14:26] C:\DOCUME~1\JORTMA~1\APPLIC~1\Identities
[07/05/2008|19:01] C:\DOCUME~1\JORTMA~1\APPLIC~1\LimeWire
[05/04/2008|21:11] C:\DOCUME~1\JORTMA~1\APPLIC~1\Logitech
[05/04/2008|23:35] C:\DOCUME~1\JORTMA~1\APPLIC~1\Macromedia
[12/05/2008|11:02] C:\DOCUME~1\JORTMA~1\APPLIC~1\Microsoft
[05/04/2008|22:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\Mozilla
[26/04/2008|19:59] C:\DOCUME~1\JORTMA~1\APPLIC~1\Sun
[05/04/2008|20:57] C:\DOCUME~1\JORTMA~1\APPLIC~1\TuneUp Software
[06/04/2008|14:56] C:\DOCUME~1\JORTMA~1\APPLIC~1\vlc
[05/04/2008|14:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[05/04/2008|14:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[05/04/2008 22:56][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[13/05/2008 20:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[01/05/2008|16:07] C:\Program Files\Adobe
[05/04/2008|20:20] C:\Program Files\Alwil Software
[05/04/2008|22:56] C:\Program Files\Apple Software Update
[01/05/2008|11:31] C:\Program Files\Atari
[05/04/2008|20:45] C:\Program Files\ATI Technologies
[05/04/2008|20:24] C:\Program Files\AvRack
[01/05/2008|11:32] C:\Program Files\BitComet
[19/04/2008|22:55] C:\Program Files\Call of Duty Game of the Year Edition
[05/04/2008|23:02] C:\Program Files\CCleaner
[05/04/2008|14:20] C:\Program Files\ComPlus Applications
[05/04/2008|22:33] C:\Program Files\DAEMON Tools Lite
[09/04/2008|14:33] C:\Program Files\DOSBox-0.72
[10/05/2008|00:43] C:\Program Files\eMule
[05/04/2008|22:59] C:\Program Files\ESTsoft
[01/05/2008|16:09] C:\Program Files\Fichiers communs
[13/05/2008|19:01] C:\Program Files\GameSpy Arcade
[10/05/2008|22:41] C:\Program Files\InstallShield Installation Information
[13/04/2008|02:47] C:\Program Files\Internet Explorer
[05/04/2008|23:04] C:\Program Files\iPod
[05/04/2008|23:04] C:\Program Files\iTunes
[23/04/2008|11:51] C:\Program Files\Java
[12/04/2008|01:47] C:\Program Files\LimeWire
[05/04/2008|20:48] C:\Program Files\Logitech
[05/04/2008|20:28] C:\Program Files\Marvell
[10/04/2008|00:40] C:\Program Files\Messenger
[13/05/2008|20:18] C:\Program Files\Messenger Plus! Live
[05/04/2008|14:23] C:\Program Files\microsoft frontpage
[09/04/2008|18:45] C:\Program Files\Microsoft Office
[05/04/2008|21:07] C:\Program Files\Movie Maker
[13/05/2008|20:35] C:\Program Files\Mozilla Firefox
[09/04/2008|14:57] C:\Program Files\MSECache
[05/04/2008|14:20] C:\Program Files\MSN
[05/04/2008|14:20] C:\Program Files\MSN Gaming Zone
[07/05/2008|15:46] C:\Program Files\Navilog1
[05/04/2008|21:06] C:\Program Files\NetMeeting
[10/04/2008|00:39] C:\Program Files\Outlook Express
[05/04/2008|23:02] C:\Program Files\QuickTime
[05/04/2008|20:21] C:\Program Files\Realtek Sound Manager
[05/04/2008|14:20] C:\Program Files\Services en ligne
[10/05/2008|23:09] C:\Program Files\Sierra
[27/04/2008|15:38] C:\Program Files\SprayR
[01/05/2008|23:38] C:\Program Files\Stardock
[13/05/2008|19:31] C:\Program Files\Steam
[23/04/2008|15:54] C:\Program Files\TmNationsForever
[13/04/2008|01:18] C:\Program Files\TuneUp Utilities 2008
[05/04/2008|14:26] C:\Program Files\Uninstall Information
[05/04/2008|23:00] C:\Program Files\VideoLAN
[06/04/2008|12:03] C:\Program Files\Windows Live
[10/04/2008|00:39] C:\Program Files\Windows Media Player
[09/04/2008|18:44] C:\Program Files\Windows Messaging
[05/04/2008|21:06] C:\Program Files\Windows NT
[05/04/2008|14:20] C:\Program Files\WindowsUpdate
[08/04/2008|23:07] C:\Program Files\WinISO
[05/04/2008|22:13] C:\Program Files\WinRAR
[05/04/2008|14:23] C:\Program Files\xerox
[13/05/2008|19:42] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[01/05/2008|16:09] C:\Program Files\Fichiers communs\Adobe
[05/04/2008|22:56] C:\Program Files\Fichiers communs\Apple
[05/04/2008|20:48] C:\Program Files\Fichiers communs\InstallShield
[12/04/2008|01:45] C:\Program Files\Fichiers communs\Java
[05/04/2008|20:48] C:\Program Files\Fichiers communs\Logitech
[09/04/2008|18:45] C:\Program Files\Fichiers communs\Microsoft Shared
[05/04/2008|14:21] C:\Program Files\Fichiers communs\MSSoap
[05/04/2008|15:15] C:\Program Files\Fichiers communs\ODBC
[29/04/2008|11:49] C:\Program Files\Fichiers communs\PocketSoft
[05/04/2008|14:21] C:\Program Files\Fichiers communs\Services
[05/04/2008|15:15] C:\Program Files\Fichiers communs\SpeechEngines
[10/04/2008|00:39] C:\Program Files\Fichiers communs\System
[06/04/2008|12:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[05/04/2008|22:02] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 38
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 20:54:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:233][Doss:6] C:\DOCUME~1\JORTMA~1\LOCALS~1\Temp
/!\ [Fich:84][Doss:0] C:\DOCUME~1\JORTMA~1\Cookies
/!\ [Fich:2599][Doss:8] C:\DOCUME~1\JORTMA~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:54:30,25 ]----------------------
apré avoir fait loption 2
-----------------------[ Lop S&D 4.2.0-8 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : jort maxime ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 13/05/2008 | 20:53:17,59 ] [ PC : MAXIME-6Z2LZVQM ]
[ MAJ : 11-05-2008 | 18:25 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave\bend creative.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\cakebrowseclose.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\jjcbcznv.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\kindpollatomonce.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\rzyjowjr.exe
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle\soft bias.exe
Supprimé! - C:\WINDOWS\Tasks\AC662DE39185DE33.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Link Axis Bat Wave
Supprimé! - C:\DOCUME~1\JORTMA~1\APPLIC~1\gpltitle
Supprimé! - C:\Program Files\gpltitle
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[05/04/2008|15:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[13/05/2008|19:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuneUp Software
[01/05/2008|23:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{A850D4D9-871B-4234-908D-21C457767270}
[01/05/2008|16:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[05/04/2008|22:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[05/04/2008|22:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[05/04/2008|15:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[06/04/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[07/05/2008|13:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[05/04/2008|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
[06/04/2008|12:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[05/04/2008|15:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[05/04/2008|14:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/05/2008|16:09] C:\DOCUME~1\JORTMA~1\APPLIC~1\Adobe
[01/05/2008|16:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\AdobeUM
[06/04/2008|17:27] C:\DOCUME~1\JORTMA~1\APPLIC~1\Apple Computer
[29/04/2008|11:50] C:\DOCUME~1\JORTMA~1\APPLIC~1\Atari
[05/04/2008|22:31] C:\DOCUME~1\JORTMA~1\APPLIC~1\DAEMON Tools
[05/04/2008|15:15] C:\DOCUME~1\JORTMA~1\APPLIC~1\desktop.ini
[11/05/2008|21:13] C:\DOCUME~1\JORTMA~1\APPLIC~1\dvdcss
[06/04/2008|21:08] C:\DOCUME~1\JORTMA~1\APPLIC~1\ESTSoft
[05/04/2008|14:26] C:\DOCUME~1\JORTMA~1\APPLIC~1\Identities
[07/05/2008|19:01] C:\DOCUME~1\JORTMA~1\APPLIC~1\LimeWire
[05/04/2008|21:11] C:\DOCUME~1\JORTMA~1\APPLIC~1\Logitech
[05/04/2008|23:35] C:\DOCUME~1\JORTMA~1\APPLIC~1\Macromedia
[12/05/2008|11:02] C:\DOCUME~1\JORTMA~1\APPLIC~1\Microsoft
[05/04/2008|22:10] C:\DOCUME~1\JORTMA~1\APPLIC~1\Mozilla
[26/04/2008|19:59] C:\DOCUME~1\JORTMA~1\APPLIC~1\Sun
[05/04/2008|20:57] C:\DOCUME~1\JORTMA~1\APPLIC~1\TuneUp Software
[06/04/2008|14:56] C:\DOCUME~1\JORTMA~1\APPLIC~1\vlc
[05/04/2008|14:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[05/04/2008|14:22] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[05/04/2008 22:56][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[13/05/2008 20:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[28/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[01/05/2008|16:07] C:\Program Files\Adobe
[05/04/2008|20:20] C:\Program Files\Alwil Software
[05/04/2008|22:56] C:\Program Files\Apple Software Update
[01/05/2008|11:31] C:\Program Files\Atari
[05/04/2008|20:45] C:\Program Files\ATI Technologies
[05/04/2008|20:24] C:\Program Files\AvRack
[01/05/2008|11:32] C:\Program Files\BitComet
[19/04/2008|22:55] C:\Program Files\Call of Duty Game of the Year Edition
[05/04/2008|23:02] C:\Program Files\CCleaner
[05/04/2008|14:20] C:\Program Files\ComPlus Applications
[05/04/2008|22:33] C:\Program Files\DAEMON Tools Lite
[09/04/2008|14:33] C:\Program Files\DOSBox-0.72
[10/05/2008|00:43] C:\Program Files\eMule
[05/04/2008|22:59] C:\Program Files\ESTsoft
[01/05/2008|16:09] C:\Program Files\Fichiers communs
[13/05/2008|19:01] C:\Program Files\GameSpy Arcade
[10/05/2008|22:41] C:\Program Files\InstallShield Installation Information
[13/04/2008|02:47] C:\Program Files\Internet Explorer
[05/04/2008|23:04] C:\Program Files\iPod
[05/04/2008|23:04] C:\Program Files\iTunes
[23/04/2008|11:51] C:\Program Files\Java
[12/04/2008|01:47] C:\Program Files\LimeWire
[05/04/2008|20:48] C:\Program Files\Logitech
[05/04/2008|20:28] C:\Program Files\Marvell
[10/04/2008|00:40] C:\Program Files\Messenger
[13/05/2008|20:18] C:\Program Files\Messenger Plus! Live
[05/04/2008|14:23] C:\Program Files\microsoft frontpage
[09/04/2008|18:45] C:\Program Files\Microsoft Office
[05/04/2008|21:07] C:\Program Files\Movie Maker
[13/05/2008|20:35] C:\Program Files\Mozilla Firefox
[09/04/2008|14:57] C:\Program Files\MSECache
[05/04/2008|14:20] C:\Program Files\MSN
[05/04/2008|14:20] C:\Program Files\MSN Gaming Zone
[07/05/2008|15:46] C:\Program Files\Navilog1
[05/04/2008|21:06] C:\Program Files\NetMeeting
[10/04/2008|00:39] C:\Program Files\Outlook Express
[05/04/2008|23:02] C:\Program Files\QuickTime
[05/04/2008|20:21] C:\Program Files\Realtek Sound Manager
[05/04/2008|14:20] C:\Program Files\Services en ligne
[10/05/2008|23:09] C:\Program Files\Sierra
[27/04/2008|15:38] C:\Program Files\SprayR
[01/05/2008|23:38] C:\Program Files\Stardock
[13/05/2008|19:31] C:\Program Files\Steam
[23/04/2008|15:54] C:\Program Files\TmNationsForever
[13/04/2008|01:18] C:\Program Files\TuneUp Utilities 2008
[05/04/2008|14:26] C:\Program Files\Uninstall Information
[05/04/2008|23:00] C:\Program Files\VideoLAN
[06/04/2008|12:03] C:\Program Files\Windows Live
[10/04/2008|00:39] C:\Program Files\Windows Media Player
[09/04/2008|18:44] C:\Program Files\Windows Messaging
[05/04/2008|21:06] C:\Program Files\Windows NT
[05/04/2008|14:20] C:\Program Files\WindowsUpdate
[08/04/2008|23:07] C:\Program Files\WinISO
[05/04/2008|22:13] C:\Program Files\WinRAR
[05/04/2008|14:23] C:\Program Files\xerox
[13/05/2008|19:42] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[01/05/2008|16:09] C:\Program Files\Fichiers communs\Adobe
[05/04/2008|22:56] C:\Program Files\Fichiers communs\Apple
[05/04/2008|20:48] C:\Program Files\Fichiers communs\InstallShield
[12/04/2008|01:45] C:\Program Files\Fichiers communs\Java
[05/04/2008|20:48] C:\Program Files\Fichiers communs\Logitech
[09/04/2008|18:45] C:\Program Files\Fichiers communs\Microsoft Shared
[05/04/2008|14:21] C:\Program Files\Fichiers communs\MSSoap
[05/04/2008|15:15] C:\Program Files\Fichiers communs\ODBC
[29/04/2008|11:49] C:\Program Files\Fichiers communs\PocketSoft
[05/04/2008|14:21] C:\Program Files\Fichiers communs\Services
[05/04/2008|15:15] C:\Program Files\Fichiers communs\SpeechEngines
[10/04/2008|00:39] C:\Program Files\Fichiers communs\System
[06/04/2008|12:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[05/04/2008|22:02] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 38
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 20:54:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:233][Doss:6] C:\DOCUME~1\JORTMA~1\LOCALS~1\Temp
/!\ [Fich:84][Doss:0] C:\DOCUME~1\JORTMA~1\Cookies
/!\ [Fich:2599][Doss:8] C:\DOCUME~1\JORTMA~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 20:54:30,25 ]----------------------
Evite de télécharger ;) C'est mauvais pour ton PC
LimeWire, BitComet, eMule, ça fait beaucoup :)
Poste un rapport HijackThis stp.
Comment se comporte le PC ?
LimeWire, BitComet, eMule, ça fait beaucoup :)
Poste un rapport HijackThis stp.
Comment se comporte le PC ?
voila
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:13:44, on 13/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Steam\steam.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:13:44, on 13/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Steam\steam.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
pour le téléchargement c'est juste qu'il sont instaler car je télécharge pas tant que cela fin bref jy pencerai a l'avenir pour l'instant ca a l'air pas mal mais si elle revienne il sufit de refaire la meme procedure ? je supose qu il y a rien de plus a faire ?
en tous cas merci de votre aide
en tous cas merci de votre aide
Le rapport est plutôt clean.
On va vérifier :
BitDefender
Fais un scan en ligne Bitdefender
https://www.bitdefender.fr/
Une fois sur le site clique sur le bouton BitDefender Scan Online
Vois la démo de Balltrap34 ici si tu n'y arrives pas !
http://pageperso.aol.fr/balltrap34/defender.htm
Copie/colle le rapport final.
Comment se comporte le PC ?
Mets également à jour ta version d'IE.
Lance Windows Update pour ce faire.
On va vérifier :
BitDefender
Fais un scan en ligne Bitdefender
https://www.bitdefender.fr/
Une fois sur le site clique sur le bouton BitDefender Scan Online
Vois la démo de Balltrap34 ici si tu n'y arrives pas !
http://pageperso.aol.fr/balltrap34/defender.htm
Copie/colle le rapport final.
Comment se comporte le PC ?
Mets également à jour ta version d'IE.
Lance Windows Update pour ce faire.