Rapport Hijack this

Résolu/Fermé
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014 - 9 juin 2008 à 11:27
 Utilisateur anonyme - 11 juin 2008 à 12:22
Bonjour,
J'ai fait une restauration du systeme, et lancé hijack this en mode sans echec, voisci le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:11, on 09/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\ERIC\Bureau\Anti-virus\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\ERIC\lsass.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [BM73411f46] Rundll32.exe "C:\WINDOWS\system32\yrxloagf.dll",s
O4 - HKLM\..\Run: [70722cda] rundll32.exe "C:\WINDOWS\system32\caxdvods.dll",b
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-f2a4c256dc63c678.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bw+0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

52 réponses

naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
9 juin 2008 à 21:55
Je l'ai fait, puis au bout d'1h30 (au moins !!) une fenetre s'est ouverte en disant : erreur (et un chiffre) Indice en dehors de la page.

Je Dois recommencer ?!
0
Utilisateur anonyme
10 juin 2008 à 15:09
Essaie de recommencer oui et en mode normal si ça fonctionne toujours pas.
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 15:17
Ok, je le fait alors.
j'ai désinstaller avast et installer antivir, il m'a trouvé pas mal de choses. J'ai mis en quarantaine. Est ce que tu veux le rapport ?
0
hubertaaz Messages postés 8194 Date d'inscription vendredi 12 mai 2006 Statut Contributeur sécurité Dernière intervention 22 janvier 2014 1 600
10 juin 2008 à 15:33
Salut à vous deux,

Je me permets une petite incruste compte tenu du fait que j'avais assisté naiki31 sur un autre topic et que je lui ai conseillé de poster ici.

naiki, je ne connaissais pas 12.eleven, mais je peux te dire que tu es pris en charge par quelqu'un qui s'y connait. Tu as beaucoup de chance.

Pour avancer 12.eleven, oui naiki31, colle ton rapport antivir.

Je tenais à vous signaler que actuellement il y a un problème pour scanner avec MalwareBytes : http://www.commentcamarche.net/forum/affich 6815607 probleme sur malwarebytes anti malware

Bonne continuation

@+
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
10 juin 2008 à 15:38
Merci Hubertaaz, il me tracassait ce message d'erreur.
Et merci pour antivir ;)

Naiki31, excellent initiative que d'avoir installer Antivir.
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 15:38
Donc voila le rapport d'antivir : il a detecté 2x Navilog que j'ai ignoré. Le reste j'ai mis en quarantaine.



Avira AntiVir Personal
Report file date: mardi 10 juin 2008 11:13

Scanning for 1320174 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: MLYNARCZ-PERSO

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
ANTIVIR2.VDF : 7.0.4.120 2206720 Bytes 01/06/2008 20:06:39
ANTIVIR3.VDF : 7.0.4.165 237568 Bytes 09/06/2008 20:06:41
Engineversion : 8.1.0.55
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.40 266618 Bytes 09/06/2008 20:06:53
AESCN.DLL : 8.1.0.21 119156 Bytes 09/06/2008 20:06:52
AERDL.DLL : 8.1.0.20 418165 Bytes 09/06/2008 20:06:52
AEPACK.DLL : 8.1.1.5 364918 Bytes 09/06/2008 20:06:51
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 09/06/2008 20:06:49
AEHEUR.DLL : 8.1.0.30 1253750 Bytes 09/06/2008 20:06:48
AEHELP.DLL : 8.1.0.15 115063 Bytes 09/06/2008 20:06:44
AEGEN.DLL : 8.1.0.28 307572 Bytes 09/06/2008 20:06:44
AEEMU.DLL : 8.1.0.6 430451 Bytes 09/06/2008 20:06:43
AECORE.DLL : 8.1.0.31 168310 Bytes 09/06/2008 20:06:42
AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: mardi 10 juin 2008 11:13

Starting search for hidden objects.
'55115' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Integrator.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'sp_rsser.exe' - '1' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'a2service.exe' - '1' Module(s) have been scanned
Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'soundman.exe' - '1' Module(s) have been scanned
Scan process 'VTTimer.exe' - '1' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Master boot sector HD2
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.
Master boot sector HD5
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '29' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\ERIC\Local Settings\Temporary Internet Files\Content.IE5\012PAJKB\Navilog1[1].exe
[DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.99
[WARNING] The file was ignored!
C:\Documents and Settings\ERIC\Local Settings\Temporary Internet Files\Content.IE5\I74J8JA7\kb456456[1]
[DETECTION] Is the Trojan horse TR/Mondera.101376
[NOTE] The file was moved to '48824893.qua'!
C:\Documents and Settings\ERIC\Local Settings\Temporary Internet Files\Content.IE5\I74J8JA7\kb516107[1]
[DETECTION] Is the Trojan horse TR/Mondera.105472.1
[NOTE] The file was moved to '48834897.qua'!
C:\Documents and Settings\ERIC\Local Settings\Temporary Internet Files\Content.IE5\IJN67NX7\kb767887[1]
[DETECTION] Is the Trojan horse TR/Mondera.113664
[NOTE] The file was moved to '488548ac.qua'!
C:\Documents and Settings\ERIC\Shared\Autre\Autre\6 Chattes en Feu.avi
[DETECTION] Is the Trojan horse TR/Dldr.WMA.GetCodec.A
[NOTE] The file was deleted!
C:\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/jkkIXnmk.dll
[DETECTION] Is the Trojan horse TR/WinlogonHook.H.1
[WARNING] The file was ignored!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP488\A0278727.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '48804c28.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP489\A0278902.exe
[DETECTION] Is the Trojan horse TR/Drop.Agen.152576
[NOTE] The file was moved to '48804c59.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP495\A0283390.dll
[DETECTION] Is the Trojan horse TR/Mondera.108544
[NOTE] The file was moved to '48804c84.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283439.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '48805071.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283442.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '48805079.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283444.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4880507c.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283445.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4880507f.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283446.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '48805082.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283447.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '48805086.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283448.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488050d2.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283449.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488050d5.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283450.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488050d7.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283451.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488050da.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP498\A0285606.dll
[DETECTION] Is the Trojan horse TR/Vundo.enl.3
[NOTE] The file was moved to '488050e3.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP498\A0285608.dll
[DETECTION] Is the Trojan horse TR/Vundo.enl.3
[NOTE] The file was moved to '488050e9.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0287284.dll
[DETECTION] Is the Trojan horse TR/Mondera.106496
[NOTE] The file was moved to '48805115.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0287285.dll
[DETECTION] Is the Trojan horse TR/Mondera.102400
[NOTE] The file was moved to '48805117.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288472.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '4880511f.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288473.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '48805122.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288474.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '48805124.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288475.dll
[DETECTION] Is the Trojan horse TR/WinlogonHook.H.1
[NOTE] The file was moved to '48805128.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288476.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '4880512a.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288477.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '48805130.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288478.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '49091749.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288479.dll
[DETECTION] Is the Trojan horse TR/WinlogonHook.H.1
[NOTE] The file was moved to '48805132.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288480.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '4909174b.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288481.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '48805131.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP501\A0288482.exe
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '4909174a.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288744.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[NOTE] The file was moved to '4880513a.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288748.exe
[DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.99
[NOTE] The file was moved to '4880513b.qua'!
C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288749.dll
[DETECTION] Is the Trojan horse TR/Mondera.113664
[NOTE] The file was moved to '49091744.qua'!
C:\WINDOWS\system32\fjbacmto.dll
[DETECTION] Is the Trojan horse TR/Mondera.108544
[NOTE] The file was moved to '48b0527d.qua'!
C:\WINDOWS\system32\ohhspuwc.VIR
[DETECTION] Is the Trojan horse TR/Mondera.113664
[NOTE] The file was moved to '48b65291.qua'!
C:\WINDOWS\system32\upgxdihq.dll.ren
[DETECTION] Is the Trojan horse TR/Mondera.108544
[NOTE] The file was moved to '48b552a4.qua'!
C:\_OTMoveIt\MovedFiles\06092008_151335\windows\system32\caxdvods.dll
[DETECTION] Is the Trojan horse TR/Mondera.101376
[NOTE] The file was moved to '48c652e3.qua'!
C:\_OTMoveIt\MovedFiles\06092008_151335\windows\system32\yrxloagf.dll
[DETECTION] Is the Trojan horse TR/Mondera.105472.1
[NOTE] The file was moved to '48c652f4.qua'!


End of the scan: mardi 10 juin 2008 12:08
Used time: 54:24 min

The scan has been done completely.

6098 Scanning directories
183070 Files were scanned
42 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
1 files were deleted
0 files were repaired
39 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
183028 Files not concerned
1461 Archives were scanned
8 Warnings
40 Notes
55115 Objects were scanned with rootkit scan
0 Hidden objects were found
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 15:40
Oui, j'ai regardé pas mal le forum, et j'ai lu comme quoi il était gratuit et mieux, donc tant qu'a faire ...
Par contre j'ai toujours pas compris moi pour ce message d'erreur ! J'ai lancé malwarebytes en mode normal.
0
Utilisateur anonyme
10 juin 2008 à 15:45
Poste un nouveau rappôrt HijackThis please :)
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 15:51
Le voici !!
Celui de Malware devrait pas tarder !

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50:49, on 10/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Glary Utilities\Integrator.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\ERIC\Bureau\Anti-virus\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {29BAA82E-2E5C-48B6-A403-56E5D34E8E92} - C:\WINDOWS\system32\qoMghiii.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: {749882ae-d757-80aa-7a94-95423632483b} - {b3842363-2459-49a7-aa08-757dea288947} - C:\WINDOWS\system32\ohhspuwc.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-f2a4c256dc63c678.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bw+0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 15:53
Et voila celui de malware :

Malwarebytes' Anti-Malware 1.15
Version de la base de données: 842

15:53:29 10/06/2008
mbam-log-6-10-2008 (15-53-29).txt

Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Eléments examinés: 100283
Temps écoulé: 34 minute(s), 43 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
Utilisateur anonyme
10 juin 2008 à 16:10
Relance HijackThis > Do a system scan only
Coche ces lignes :
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {29BAA82E-2E5C-48B6-A403-56E5D34E8E92} - C:\WINDOWS\system32\qoMghiii.dll (file missing)
O2 - BHO: {749882ae-d757-80aa-7a94-95423632483b} - {b3842363-2459-49a7-aa08-757dea288947} - C:\WINDOWS\system32\ohhspuwc.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O18 - Protocol: bw+0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {193B3AEC-43E9-4F64-82E9-993C80F44198} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
Clique sur Fix Checked



BitDefender
#Fais un scan en ligne Bitdefender
#Une fois sur le site clique sur le bouton BitDefender Scan Online
#Vois la démo de Balltrap34 ici si tu n'y arrives pas !
#Copie/colle le rapport final.

NB : Le scan est à faire avec Internet Explorer
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 19:06
Bon alors j'ai fait le scan de Bit defender. A la fin j'ai cliquer sur envoyer le rapport, la fenetre s'est fermée. Il se trouve ou normalement ?!
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 19:16
G trouvé ca sur l'ordi sous forme html




BitDefender Online Scanner

Rapport d'analyse généré à: Tue, Jun 10, 2008 - 17:44:56

Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;


Statistiques

Temps


01:25:09

Fichiers


77177

Directoires


6197

Secteurs de boot


2

Archives


1519

Paquets programmes


5017







Résultats

Virus identifiés


5

Fichiers infectés


6

Fichiers suspects


0

Avertissements


0

Désinfectés


0

Fichiers effacés


6







Info sur les moteurs

Définition virus


1257267

Version des moteurs


AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Analyse des plugins


16

Archive des plugins


42

Unpack des plugins


7

E-mail plugins


6

Système plugins


5







Paramètres d'analyse

Première action


Désinfecté

Seconde Action


Supprimé

Heuristique


Oui

Acceptez les avertissements


Oui

Extensions analysées


exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

Excludez les extensions




Analyse d'emails


Oui

Analyse des Archives


Oui

Analyser paquets programmes


Oui

Analyse des fichiers


Oui

Analyse de boot


Oui








Fichier analysé


Statut

C:\LOGICIELS LIBRES\EDUCATIF\CARTES DU CIEL\cdcbase276.exe


Infecté par: Trojan.Generic.272855

C:\LOGICIELS LIBRES\EDUCATIF\CARTES DU CIEL\cdcbase276.exe


Supprimé

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP496\A0283415.dll


Infecté par: Trojan.Vundo.ESP

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP496\A0283415.dll


Supprimé

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283441.dll


Infecté par: Rootkit.1007

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283441.dll


Supprimé

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP500\A0287077.dll


Infecté par: MemScan:Trojan.Vundo.ESK

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP500\A0287077.dll


Supprimé

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288842.exe


Infecté par: Trojan.Generic.272855

C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288842.exe


Supprimé

C:\Temp\hEmm0012.exe


Infecté par: MemScan:Trojan.Downloader.Small.BUY

C:\Temp\hEmm0012.exe


Supprimé
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 19:17
Et celui la sous forme log (ce n'est pas la meme presentation mais en gros ya marqué la meme chose !


[General]
App = "BitDefender Online Scanner v8"
Date = 10:06:2008
Time = 17:44:56
Scan Path = C:\;D:\;E:\;F:\;G:\;H:\;I:\;

[Engines Info]
Virus Definitions = 1257267
Engine build = "AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)"
Scan plugins = 16
Archive plugins = 42
Unpack plugins = 7
E-mail plugins = 6
System plugins = 5

[Scan Statistics]
Folders = 6197
Files = 77177
Archives = 1519
Packed files = 5017
Identified viruses = 5
Infected files = 6
Warnings = 0
Suspect files = 0
Disinfected files = 0
Deleted files = 6
Copied files = 0
Moved files = 0
Renamed files = 0
I/O Errors = 7

[Scan Settings]
SecondAction = Delete
FirstAction = Disinfect
Heuristics = 1
Enable Warnings = 1
Exclude Ext =
Extensions = exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Scan Emails = 1
Scan Archives = 1
Scan Packed = 1
Scan Files = 1
Scan Boot = 1
Verify Memory = 0

[Scan Results]
Line00000011 = "C:\LOGICIELS LIBRES\EDUCATIF\CARTES DU CIEL\cdcbase276.exe Infecté par: Trojan.Generic.272855"
Line00000010 = "C:\LOGICIELS LIBRES\EDUCATIF\CARTES DU CIEL\cdcbase276.exe Supprimé"
Line00000009 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP496\A0283415.dll Infecté par: Trojan.Vundo.ESP"
Line00000008 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP496\A0283415.dll Supprimé"
Line00000007 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283441.dll Infecté par: Rootkit.1007"
Line00000006 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP497\A0283441.dll Supprimé"
Line00000005 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP500\A0287077.dll Infecté par: MemScan:Trojan.Vundo.ESK"
Line00000004 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP500\A0287077.dll Supprimé"
Line00000003 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288842.exe Infecté par: Trojan.Generic.272855"
Line00000002 = "C:\System Volume Information\_restore{CEEFC400-7250-4EB9-8206-F73F4C99AFE3}\RP503\A0288842.exe Supprimé"
Line00000001 = "C:\Temp\hEmm0012.exe Infecté par: MemScan:Trojan.Downloader.Small.BUY"
Line00000000 = "C:\Temp\hEmm0012.exe Supprimé"
0
Utilisateur anonyme
10 juin 2008 à 19:52
Et maintenant, le PC, comment va-t-il ?
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 20:50
Ben depuis que je l'ai rallumer ce matin je n'ai pas eu une seule pub donc apparemment ca a lair detre parfait !
Merci encore pour tout !
0
Utilisateur anonyme
10 juin 2008 à 21:07
* Je t'invite à lire ceci :
*https://www.malekal.com/proteger-pc-virus-pirates/
*http://forum.telecharger.01net.com/microhebdo/6/tuto-securite/mesures_preventives_avant_navigation_sinternet_et_entretien-346836/messages-1.html
*Utilise Windows Update
*Télécharge https://filehippo.com/windows/tuning-utilities/ tu l'installes et il te liste ce qu'il faut mettre à jour avec les liens correspondants.


*Télécharge ToolsCleaner (A.Rothstein) sur ton Bureau:
http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
*Clique sur Recherche et laisse le scan se terminer.
*Clique sur Suppression pour finaliser.
*Tu peux, si tu le souhaites, te servir des Options facultatives.
*Clique sur Quitter, pour que le rapport puisse se créer.
*Poste le rapport C:\TCleaner.txt

------------------------------------------------------------------------------------------­­-------------------------

1.Ouvre le Menu Démarrer
2.Clique-droit sur Poste de travail
3.Clique sur Propriétés
4.Positionne-toi dans l'onglet Restauration du système
5.Coche Désactiver la restauration système
6.Valide par Ok
7.Redémarre
8.Reproduis les manipulations 1 à 3
9.Décoche Désactiver la restauration système
10.Valide par Ok

------------------------------------------------------------------------------------------­­-------------------------

*Télécharge Ccleaner :
Clique sur le premier Download now > Choisis la version Slim
Installe Ccleaner.
Nettoie Windows et la base de registre en suivant ce tuto :
https://www.malekal.com/tutoriel-ccleaner/#mozTocId223895

------------------------------------------------------------------------------------------­­-------------------------

*Désinstalle Avast!
https://www.avast.com/fr-fr/uninstall-utility

*Installe Antivir
https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html
https://www.malekal.com/avira-free-security-antivirus-gratuit/
*Paramètre le
https://www.astucesinternet.com/modules/news/article.php?storyid=253
*Quand Antivir se met à jour, il affiche une popup. Voilà comment la supprimer :
https://forum.malekal.com/viewtopic.php?p=45326

*Antivir VS Avast!
http://forum.malekal.com/ftopic3528.php
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 21:25
J'avais deja Ccleaner, je l'utilise de temps en temps, et j'avait trouvé un tuto pour installer antivir en désinstallant avast donc c'est fait aussi !

Voici le rapport de Tcleaner :

-->- Recherche:

C:\SDFIX: trouvé !
C:\Vundofix backups: trouvé !
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
C:\Documents and Settings\ERIC\Bureau\SdFix.exe: trouvé !
C:\Documents and Settings\ERIC\Bureau\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\VirtumundoBeGone.exe: trouvé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\vundoFix.exe: trouvé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\HijackThis.exe: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Navilog1\Navilog1.bat: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
C:\Documents and Settings\ERIC\Bureau\SdFix.exe: supprimé !
C:\Documents and Settings\ERIC\Bureau\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\VirtumundoBeGone.exe: supprimé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\vundoFix.exe: supprimé !
C:\Documents and Settings\ERIC\Bureau\Anti-virus\HijackThis.exe: supprimé !
C:\Program Files\Navilog1\Navilog1.bat: supprimé !
C:\SDFIX: supprimé !
C:\Vundofix backups: supprimé !
C:\_OtMoveIt: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
C:\Program Files\Navilog1: supprimé !
0
naiki31 Messages postés 69 Date d'inscription vendredi 6 juin 2008 Statut Membre Dernière intervention 28 janvier 2014
10 juin 2008 à 21:26
Par contre quand je fais clik droit sur poste de travail puis propriété, je n'ai pas "restauration du systeme"
0
Utilisateur anonyme
10 juin 2008 à 21:51
Bizarre..

Tu n'as pas d'onglet Restauration système ? Vraiment étrange
0