PROBLEME DE FENETRE IMPESTIVES

minibus22 Messages postés 18 Statut Membre -  
minibus22 Messages postés 18 Statut Membre -
Bonjour,

Au secour j'ai besoin d'aide j'ai des fenêtres intempestives (CID) qui s'ouvrent sans arrêt et je n'arrivent pas à m'en débarrasser.

J'aimerai beaucoup que quelqu'un m'aide SVP.
A voir également:

11 réponses

toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Bonjour

Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

* Enregistre HJTInstall.exe sur ton bureau.

* Double-clique sur HJTInstall.exe pour lancer le programme

Tuto : https://www.malekal.com/tutoriel-hijackthis/
http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

* Accepte la license en cliquant sur le bouton "I Accept"
* Choisis l'option "Do a system scan and save a log file"
* Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
* Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

* Colle le rapport que tu viens de copier sur ce forum
-1
minibus22 Messages postés 18 Statut Membre
 
désolé j'étais bloqué

je ne trouve pas SAVE LOG pour enregistrer le rapport et le bloc note
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Normalement le bloc note s'ouvre tout seul et tu n'as plus qu'à tout sélectionner et copier.
Si ce n'est pas le cas, tu retrouveras ton rapport (Hijackthis.log) dans :

C:\Program Files\Trend Micro\Hijackthis
-1
minibus22 Messages postés 18 Statut Membre
 
voici le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:17:24, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Télécharge Lop S&D.exe sur ton Bureau.

https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)

Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
-1
minibus22 Messages postés 18 Statut Membre
 
--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 08/10/2008|21:25 )

--------------------\\ Listing des dossiers dans APPLIC~1

[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[27/09/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[13/03/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\erreurchasseur
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real

[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe

[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[13/03/2008|19:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\erreurchasseur
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc

[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real

[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[13/03/2008|22:22] C:\Program Files\ErreurChasseur
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:08] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 43 Processes )

IEXPLORE.EXE ~ [PID:2968]
IEXPLORE.EXE ~ [PID:3184]
IEXPLORE.EXE ~ [PID:3568]

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\Gpl List.exe
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@32vegas[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.32vegas[2].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:26:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115

--------------------\\ Recherche d'autres infections

C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf

C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b

[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b

--------------------\\ ROGUES ..

C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free



[F:6][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:73][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1617][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]

--------------------\\ Fin du rapport a 21:27:59
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Relance Lop S&D

* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
-1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
minibus22 Messages postés 18 Statut Membre
 
--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [2] ( 08/10/2008|21:40 )

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[2].txt
Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[1].txt

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

--------------------\\ Listing des dossiers dans APPLIC~1

[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real

[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe

[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc

[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real

[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:36] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 38 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:41:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115

--------------------\\ Recherche d'autres infections

C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf

C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b

[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b

--------------------\\ ROGUES ..

C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free

[F:5][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:70][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1784][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 08/10/2008|21:35 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 08/10/2008|21:42 - Option : [2]

--------------------\\ Fin du rapport a 21:42:37
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
OK
Refais un Hijackthis stp, qu'on voit un peu où on en est.
-1
minibus22 Messages postés 18 Statut Membre
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:46:50, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Télécharge Fixwareout : http://downloads.subratam.org/Fixwareout.exe

Double clique sur Fixwareout.exe
Clique "Next", puis "Install", et vérifie que "Run fixit" soit coché, puis tu cliques "Finish".
Suis les directives à l'écran.
L'outil va te demander de redémarrer ton PC, tu redémarres.

Le redémarrage risque de prendre un peu plus de temps, ceci est normal.

Le rapport sera dans le bloc note lors du redémarrage et tu pourras le sauvegarder.

Pour copier/coller le rapport du "Bloc note" tu vas dans le menu Édition et clique sur "Sélectionner tout" et retourne dans "Édition" et clique sur "copier"
Sur le forum, faire un click droit et cliquer sur "coller".
-1
minibus22 Messages postés 18 Statut Membre
 
Username "HP_Propri‚taire" - 08/10/2008 21:59:07 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.163 85.255.112.176" <Value cleared.

Cache de résolution DNS vidé.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"EPSON Stylus CX3600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9BE.EXE /P26 \"EPSON Stylus CX3600 Series\" /M \"Stylus CX3600\" /EF \"HKCU\""
"ccleaner"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /AUTO"
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background"
"drv spam"="C:\\DOCUME~1\\HP_PRO~1\\APPLIC~1\\INTERN~1\\heart logo.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
-1
minibus22 Messages postés 18 Statut Membre
 
as tu bien eu le dernier rapport
-1
minibus22 Messages postés 18 Statut Membre
 
Je vais devoir en rester la pour ce soir je me reconnecterai demain pour savoir si on avais bien terminer.

Merci quand même

A demain
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
Refais un Hijackthis stp.
-1
minibus22 Messages postés 18 Statut Membre
 
bonjour,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:56, on 09/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.9 80.10.246.132
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
-1
toptitbal Messages postés 26224 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 232
 
télécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe
de Old_Timer) sur ton Bureau.

Relance HijackThis.

Clique sur Scan Only et coche la ligne suivante :

O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe

Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connection Internet.

Clique sur Fix checked puis clique sur OK
Puis ferme HijackThis.

Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.

C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe

clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.

-1
minibus22 Messages postés 18 Statut Membre
 
Error: Unable to interpret <C:DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe> in the current context!

OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10092008_120359
-1