Antispyware Expert & more - Page 2

Résolu
  1. le PC avait bien redemare; je continue
    0
    1. voici le log OTmoveit:

      DllUnregisterServer procedure not found in C:\WINDOWS\system32\geBqPFYq.dll
      C:\WINDOWS\system32\geBqPFYq.dll NOT unregistered.
      C:\WINDOWS\system32\geBqPFYq.dll moved successfully.
      DllUnregisterServer procedure not found in C:\WINDOWS\system32\apymwcfw.dll
      C:\WINDOWS\system32\apymwcfw.dll NOT unregistered.
      C:\WINDOWS\system32\apymwcfw.dll moved successfully.

      OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06222008_015056
      0
      1. Contributeur sécurité
        Bien...

        Refais moi un log HJT tout frais stp...

        Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
        Choisis l'option "Do a system scan and save a log file"
        Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
        Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici

        Comment fixer les lignes et Générer un rapport <---- voir ici
        0
        1. le voici:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 01:58:03, on 22.06.2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
          C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Softwin\BitDefender10\bdmcon.exe
          C:\Program Files\Softwin\BitDefender10\bdagent.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
          C:\WINDOWS\system32\Rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
          C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
          C:\Program Files\Softwin\BitDefender10\vsserv.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.yahoo.com/?p=us
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = yahoo!
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {08A5C3F9-9A65-4F0A-A045-8E38DFD2DACE} - C:\WINDOWS\system32\geBqPFYq.dll (file missing)
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
          O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
          O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
          O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
          O4 - HKLM\..\Run: [BMe387bf97] Rundll32.exe "C:\WINDOWS\system32\apymwcfw.dll",s
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
          O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
          O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
          O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
          O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
          O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
          O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
          O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll (file missing)
          O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll (file missing)
          O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
          0
          1. Coriace, on dirait...

            O4 - HKLM\..\Run: [BMe387bf97] Rundll32.exe "C:\WINDOWS\system32\apymwcfw.dll",s
            0
            1. Jorginho, est-ce que tu as une idee de ce que je peux encore faire pour supprimer ce qui reste?
              Dans tous les cas, merci pour ton aide - je ne vais pas tarder a me coucher...
              0
              1. pk - j'ai compirs - les virus ne sont plus la. Il a suffi de redemarrer et faire un "fix" avec hijack pour avoir un rapport clean;

                Merci BEAUCOUP pour ton aide, ainis qu'aux autres!!!!!

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 02:26:18, on 22.06.2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                C:\Program Files\Softwin\BitDefender10\bdagent.exe
                C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Skype\Phone\Skype.exe
                C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\Program Files\Softwin\BitDefender10\vsserv.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Program Files\Skype\Plugin Manager\skypePM.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.yahoo.com/?p=us
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = yahoo!
                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
                O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
                O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll (file missing)
                O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\SmartShopper\Bin\2.0.20\SmrtShpr.dll (file missing)
                O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                0
                1. Contributeur sécurité
                  C'est toi qui a mis Yahoo en page d'acceuil ?
                  0
                  1. je crois que c on pere ;) c'est sa machine...
                    0
                    1. Merci encore! Je pense que nous pouvons marquer "pb resolu" pour ce thread.
                      0
                      1. Ok, le "cas" est officielement reouvert ;)

                        Voici le log combofix:

                        ComboFix 08-06-20.4 - Alex 2008-06-22 16:20:44.1 - NTFSx86
                        Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.251 [GMT 3:00]
                        Running from: C:\Documents and Settings\Alex\Desktop\ComboFix.exe

                        [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
                        .

                        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        C:\WINDOWS\BMe387bf97.xml
                        C:\WINDOWS\cookies.ini
                        C:\WINDOWS\pskt.ini
                        C:\WINDOWS\system32\eviliiwn.ini
                        C:\WINDOWS\system32\hawetffe.ini
                        C:\WINDOWS\system32\mcrh.tmp
                        C:\WINDOWS\system32\nvenebiy.ini
                        C:\WINDOWS\system32\pc.dll
                        C:\WINDOWS\system32\pxkvesui.ini
                        C:\WINDOWS\system32\pyrripda.ini
                        C:\WINDOWS\system32\qYFPqBeg.ini
                        C:\WINDOWS\system32\qYFPqBeg.ini2
                        C:\WINDOWS\system32\tjbagxuj.ini
                        C:\WINDOWS\system32\vtfwhfnk.ini
                        C:\WINDOWS\system32\XIOopqss.ini
                        C:\WINDOWS\system32\XIOopqss.ini2

                        .
                        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        -------\Legacy_DRV

                        ((((((((((((((((((((((((( Files Created from 2008-05-22 to 2008-06-22 )))))))))))))))))))))))))))))))
                        .

                        2008-06-22 01:50 . 2008-06-22 01:50 <DIR> d-------- C:\_OTMoveIt
                        2008-06-22 00:08 . 2008-06-22 00:08 <DIR> d-------- C:\Program Files\Trend Micro
                        2008-06-21 21:24 . 2008-06-21 21:24 81,408 --a------ C:\WINDOWS\system32\adpirryp.dll
                        2008-06-21 20:13 . 2008-06-21 20:13 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                        2008-06-21 20:13 . 2008-06-21 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                        2008-06-21 20:13 . 2008-06-21 20:13 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
                        2008-06-21 20:13 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                        2008-06-21 20:13 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                        2008-06-21 12:35 . 2008-06-22 16:45 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                        2008-06-21 12:35 . 2008-06-21 12:35 1,409 --a------ C:\WINDOWS\QTFont.for
                        2008-06-20 18:40 . 2008-06-20 18:40 90,112 --a------ C:\WINDOWS\system32\trvsfdio.dll
                        2008-06-20 15:37 . 2008-06-20 17:42 <DIR> d-------- C:\Documents and Settings\Alex\.housecall6.6
                        2008-06-19 00:02 . 2008-06-19 00:02 <DIR> d-------- C:\Program Files\Lavasoft
                        2008-06-19 00:02 . 2008-06-19 00:02 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Lavasoft
                        2008-06-18 08:14 . 2008-06-18 08:14 1,633,992 --ahs---- C:\WINDOWS\system32\nvenebiy.tmp
                        2008-06-18 03:17 . 2008-06-18 03:17 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Uniblue
                        2008-06-18 02:36 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
                        2008-06-18 00:45 . 2008-06-18 02:16 1,956 --ahs---- C:\WINDOWS\system32\FhhNqqss.ini
                        2008-06-17 23:25 . 2008-06-17 23:25 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Talkback
                        2008-06-17 23:24 . 2008-06-17 23:24 0 --a------ C:\WINDOWS\nsreg.dat
                        2008-06-17 23:08 . 2008-06-17 23:08 <DIR> d-------- C:\Program Files\PCTV4Me
                        2008-06-17 23:08 . 2008-06-17 23:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PCTV4Me
                        2008-06-17 23:08 . 2008-06-17 23:08 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\PCTV4Me
                        2008-06-17 22:52 . 2008-06-17 22:52 33,280 --a------ C:\WINDOWS\system32\cbXPiIba.dll.vir
                        2008-06-17 22:10 . 2008-06-19 00:00 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\BitTorrent
                        2008-06-11 19:17 . 2008-04-14 14:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
                        2008-05-27 02:30 . 2008-05-27 02:30 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
                        2008-05-27 02:29 . 2008-05-27 02:29 <DIR> d-------- C:\Program Files\Common Files\Skype
                        2008-05-24 01:35 . 2008-05-24 01:35 <DIR> d-------- C:\WINDOWS\Sun
                        2008-05-24 01:33 . 2008-06-18 02:36 <DIR> d-------- C:\Program Files\Java
                        2008-05-24 01:32 . 2008-05-24 01:32 <DIR> d-------- C:\Program Files\Common Files\Java

                        .
                        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2008-06-22 13:49 --------- d-----w C:\Documents and Settings\Alex\Application Data\skypePM
                        2008-06-22 13:48 --------- d-----w C:\Documents and Settings\Alex\Application Data\Skype
                        2008-06-22 13:42 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
                        2008-06-18 21:01 --------- d-----w C:\Documents and Settings\Friends\Application Data\DNA
                        2008-06-18 21:00 --------- d-----w C:\Documents and Settings\Friends\Application Data\BitTorrent
                        2008-06-18 19:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
                        2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
                        2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
                        2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
                        2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
                        2008-02-07 12:54 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
                        2007-05-17 11:42 14 ----a-w C:\Documents and Settings\Alex\getfile.dat
                        .

                        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* empty entries & legit default entries are not shown
                        REGEDIT4

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
                        "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312]
                        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22 4670968]
                        "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 21:37 68856]
                        "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 17:59 224248]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Cmaudio"="cmicnfg.cpl,CMICtrlWnd" []
                        "OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 11:00 49152]
                        "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
                        "BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-04-02 16:48 290816]
                        "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49 69632]
                        "PC Booster"="C:\Program Files\inKline Global\PC Booster\pcbooster.exe" [ ]
                        "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 17:59 224248]
                        "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
                        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
                        "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 21:37 68856]

                        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
                        Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
                        Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                        "AppInit_DLLs"=sockspy.dll

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                        "MSACM.MI-SC4"= MI-SC4.acm

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                        "AntiVirusOverride"=dword:00000001

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "C:\\Program Files\\Messenger\\msmsgs.exe"=
                        "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                        "<NO NAME>"= :Yahoo! Music Jukebox
                        "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
                        "C:\\WINDOWS\\system32\\dpvsetup.exe"=
                        "C:\\Program Files\\DNA\\btdna.exe"=
                        "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
                        "C:\\Program Files\\iTunes\\iTunes.exe"=
                        "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

                        .
                        Contents of the 'Scheduled Tasks' folder
                        "2008-06-19 13:03:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                        .
                        **************************************************************************

                        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-06-22 16:47:08
                        Windows 5.1.2600 Service Pack 2 NTFS

                        scanning hidden processes ...

                        scanning hidden autostart entries ...

                        scanning hidden files ...

                        scan completed successfully
                        hidden files: 0

                        **************************************************************************
                        .
                        ------------------------ Other Running Processes ------------------------
                        .
                        C:\WINDOWS\system32\ati2evxx.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                        C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                        C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                        C:\Program Files\Softwin\BitDefender10\vsserv.exe
                        C:\WINDOWS\system32\ati2evxx.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Skype\Plugin Manager\skypePM.exe
                        .
                        **************************************************************************
                        .
                        Completion time: 2008-06-22 16:54:53 - machine was rebooted
                        ComboFix-quarantined-files.txt 2008-06-22 13:53:51

                        Pre-Run: 2,968,055,808 bytes free
                        Post-Run: 3,826,294,784 bytes free

                        158 --- E O F --- 2008-06-11 21:14:28
                        0
                        1. Effectivement... Merci de me dire à partir de là quelles sont les étapes.
                          0
                          1. je vois que l on t as laissé tombé ...........

                            télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
                            double-clique sur OTMoveIt.exe pour le lancer.
                            copie la liste qui se trouve en gras ci-dessous,
                            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                            C:\WINDOWS\QTFont.qfn
                            C:\WINDOWS\QTFont.for
                            C:\WINDOWS\system32\FhhNqqss.ini
                            C:\WINDOWS\system32\nvenebiy.tmp
                            C:\WINDOWS\system32\cbXPiIba.dll.vir


                            clique sur MoveIt! pour lancer la suppression.
                            le résultat apparaitra dans le cadre "Results".
                            clique sur Exit pour fermer.
                            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                            il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                            0
                            1. Eh oui, c de ma faute, j'ai trop vite crie victoire ;) Merci d'etre la!
                              Voici le log Old Timer:

                              C:\WINDOWS\QTFont.qfn moved successfully.
                              C:\WINDOWS\QTFont.for moved successfully.
                              C:\WINDOWS\system32\FhhNqqss.ini moved successfully.
                              C:\WINDOWS\system32\nvenebiy.tmp moved successfully.
                              C:\WINDOWS\system32\cbXPiIba.dll.vir moved successfully.

                              OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06222008_193037
                              0
                              1. je vois que l on t as laissé tombé ...........

                                Je retire ce que g dis ....

                                * pour supprimer les outils/fix utilisés :

                                Télécharge ToolsCleaner sur ton bureau.
                                -->
                                http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe
                                http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe

                                # Clique sur Recherche et laisse le scan agir ...
                                # Clique sur Suppression pour finaliser.
                                # Tu peux, si tu le souhaites, te servir des Options facultatives.
                                # Clique sur Quitter pour obtenir le rapport.
                                # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                                0
                                1. J'ai tout supprime, mais je ne trouve pas de log a la racine C:\.
                                  0
                                  1. oki si c est supprimé c bon

                                    ciao @++
                                    0
                                    1. Merci! Ca veut dire que... c'est bon? J'ose y croire cette fois :)) ?
                                      0
                                      1. oui cette fois c bon @++
                                        0
                                        1. En tout cas - merci à tous, je trouve touché par votre aide!
                                          Heureusement que vous êtes là !!!
                                          0
                                          Précédent
                                          • 1
                                          • 2