PROBLEME DE FENETRE IMPESTIVES
minibus22
Messages postés
18
Statut
Membre
-
minibus22 Messages postés 18 Statut Membre -
minibus22 Messages postés 18 Statut Membre -
Bonjour,
Au secour j'ai besoin d'aide j'ai des fenêtres intempestives (CID) qui s'ouvrent sans arrêt et je n'arrivent pas à m'en débarrasser.
J'aimerai beaucoup que quelqu'un m'aide SVP.
Au secour j'ai besoin d'aide j'ai des fenêtres intempestives (CID) qui s'ouvrent sans arrêt et je n'arrivent pas à m'en débarrasser.
J'aimerai beaucoup que quelqu'un m'aide SVP.
A voir également:
- PROBLEME DE FENETRE IMPESTIVES
- Fenetre windows - Guide
- Fenêtre hors écran windows 11 - Guide
- Fenetre de navigation privée - Guide
- Mcafee fenetre intempestive - Accueil - Piratage
- Fermer une fenetre de force - Guide
11 réponses
Bonjour
Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
* Enregistre HJTInstall.exe sur ton bureau.
* Double-clique sur HJTInstall.exe pour lancer le programme
Tuto : https://www.malekal.com/tutoriel-hijackthis/
http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
* Accepte la license en cliquant sur le bouton "I Accept"
* Choisis l'option "Do a system scan and save a log file"
* Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
* Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
* Colle le rapport que tu viens de copier sur ce forum
Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
* Enregistre HJTInstall.exe sur ton bureau.
* Double-clique sur HJTInstall.exe pour lancer le programme
Tuto : https://www.malekal.com/tutoriel-hijackthis/
http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
* Accepte la license en cliquant sur le bouton "I Accept"
* Choisis l'option "Do a system scan and save a log file"
* Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
* Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
* Colle le rapport que tu viens de copier sur ce forum
Normalement le bloc note s'ouvre tout seul et tu n'as plus qu'à tout sélectionner et copier.
Si ce n'est pas le cas, tu retrouveras ton rapport (Hijackthis.log) dans :
C:\Program Files\Trend Micro\Hijackthis
Si ce n'est pas le cas, tu retrouveras ton rapport (Hijackthis.log) dans :
C:\Program Files\Trend Micro\Hijackthis
voici le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:17:24, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:17:24, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
Télécharge Lop S&D.exe sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 08/10/2008|21:25 )
--------------------\\ Listing des dossiers dans APPLIC~1
[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[27/09/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[13/03/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\erreurchasseur
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[13/03/2008|19:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\erreurchasseur
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc
[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[13/03/2008|22:22] C:\Program Files\ErreurChasseur
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:08] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 43 Processes )
IEXPLORE.EXE ~ [PID:2968]
IEXPLORE.EXE ~ [PID:3184]
IEXPLORE.EXE ~ [PID:3568]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\Gpl List.exe
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@32vegas[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.32vegas[2].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:26:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf
C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b
[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b
--------------------\\ ROGUES ..
C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[F:6][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:73][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1617][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]
--------------------\\ Fin du rapport a 21:27:59
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 08/10/2008|21:25 )
--------------------\\ Listing des dossiers dans APPLIC~1
[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[27/09/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[13/03/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\erreurchasseur
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[13/03/2008|19:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\erreurchasseur
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc
[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[13/03/2008|22:22] C:\Program Files\ErreurChasseur
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:08] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 43 Processes )
IEXPLORE.EXE ~ [PID:2968]
IEXPLORE.EXE ~ [PID:3184]
IEXPLORE.EXE ~ [PID:3568]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\Gpl List.exe
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[2].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@32vegas[1].txt
C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@banner.32vegas[2].txt
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:26:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf
C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b
[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b
--------------------\\ ROGUES ..
C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[F:6][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:73][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1617][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]
--------------------\\ Fin du rapport a 21:27:59
Relance Lop S&D
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [2] ( 08/10/2008|21:40 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[2].txt
Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[1].txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc
[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:36] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 38 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:41:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf
C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b
[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b
--------------------\\ ROGUES ..
C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[F:5][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:70][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1784][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 08/10/2008|21:35 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 08/10/2008|21:42 - Option : [2]
--------------------\\ Fin du rapport a 21:42:37
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3000+ )
BIOS : Phoenix - Award BIOS v6.00PG
USER : HP_Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081008-0] 4.8.1229 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total : 143 Go Free : 98 Go
D:\ (Local Disk) - FAT32 - Total : 5 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB) - FAT - Total : 245 Mo Free : 0 Go
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [2] ( 08/10/2008|21:40 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@advertising[2].txt
Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@cotedazurpalace[1].txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[04/10/2008|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
[04/10/2008|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Emjysoft
[05/10/2008|11:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[24/09/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[02/01/2005|01:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[21/09/2007|23:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[06/10/2008|12:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[15/02/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[02/01/2005|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[02/01/2005|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[18/03/2007|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[21/02/2007|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[25/07/2006|22:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[04/01/2007|12:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[07/01/2007|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[05/10/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[27/10/2005|00:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[02/01/2005|02:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
[21/04/2008|22:11] C:\DOCUME~1\HP_PRO~2\APPLIC~1\Adobe
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Adobe
[21/09/2008|10:08] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AdobeUM
[23/09/2007|22:38] C:\DOCUME~1\HP_PRO~1\APPLIC~1\aMule
[24/09/2007|13:21] C:\DOCUME~1\HP_PRO~1\APPLIC~1\AVG7
[11/07/2006|18:16] C:\DOCUME~1\HP_PRO~1\APPLIC~1\CyberLink
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DivX
[03/01/2007|17:17] C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[17/02/2008|17:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\dvdcss
[04/10/2008|12:44] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Emjysoft
[28/09/2007|13:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\F-Secure
[29/05/2007|17:30] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Google
[18/12/2006|17:41] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Help
[13/03/2007|15:01] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HP
[19/07/2006|22:40] C:\DOCUME~1\HP_PRO~1\APPLIC~1\HPQ
[14/09/2008|20:54] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Icone
[27/10/2005|00:34] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Identities
[27/09/2008|18:20] C:\DOCUME~1\HP_PRO~1\APPLIC~1\internet phone mapi
[28/09/2007|12:05] C:\DOCUME~1\HP_PRO~1\APPLIC~1\ispnews
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Leadertech
[06/10/2008|19:52] C:\DOCUME~1\HP_PRO~1\APPLIC~1\LimeWire
[04/10/2008|12:27] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Macromedia
[06/10/2008|12:07] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Malwarebytes
[28/10/2007|15:57] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Media Player Classic
[02/02/2008|22:00] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Microsoft
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla
[02/01/2007|21:28] C:\DOCUME~1\HP_PRO~1\APPLIC~1\MSNInstaller
[28/09/2007|12:11] C:\DOCUME~1\HP_PRO~1\APPLIC~1\PEX
[28/09/2007|18:23] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Real
[01/10/2008|18:55] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Samsung
[13/05/2007|12:31] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
[22/09/2006|22:06] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Smart Panel
[11/07/2006|21:59] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sonic
[02/01/2007|23:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Sun
[15/10/2007|13:43] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Talkback
[11/07/2006|19:02] C:\DOCUME~1\HP_PRO~1\APPLIC~1\Template
[24/09/2007|18:39] C:\DOCUME~1\HP_PRO~1\APPLIC~1\vlc
[27/10/2005|00:34] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[24/09/2007|20:30] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[19/07/2006|22:13] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[23/09/2007|21:24] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[24/09/2007|20:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[24/09/2007|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[08/10/2008 18:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 13:00][-rah-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[24/09/2007|20:32] C:\Program Files\Adobe
[28/10/2007|16:13] C:\Program Files\Ahead
[21/09/2007|23:14] C:\Program Files\Altnet
[21/03/2007|12:35] C:\Program Files\Alwil Software
[15/10/2007|12:56] C:\Program Files\AntivirusFirewall
[06/10/2008|12:03] C:\Program Files\CCleaner
[20/10/2005|21:06] C:\Program Files\ComPlus Applications
[31/10/2007|20:29] C:\Program Files\DivX
[27/09/2008|18:28] C:\Program Files\Dofus
[04/10/2008|12:23] C:\Program Files\eMule
[17/02/2008|10:42] C:\Program Files\epson
[04/10/2008|12:40] C:\Program Files\Fichiers communs
[04/10/2008|12:23] C:\Program Files\Free Easy Burner
[05/10/2008|11:04] C:\Program Files\Google
[21/02/2008|17:29] C:\Program Files\Grisoft
[28/09/2007|18:08] C:\Program Files\Hewlett-Packard
[28/09/2007|18:02] C:\Program Files\HP
[04/10/2008|12:18] C:\Program Files\InstallShield Installation Information
[14/08/2008|12:42] C:\Program Files\Internet Explorer
[27/09/2008|18:19] C:\Program Files\internet phone mapi
[04/10/2008|12:43] C:\Program Files\Java
[04/10/2008|12:34] C:\Program Files\JCA2000
[03/10/2006|18:49] C:\Program Files\Konami
[04/10/2008|12:38] C:\Program Files\LimeWire
[14/08/2008|12:46] C:\Program Files\Messenger
[05/10/2008|11:50] C:\Program Files\Metin2_France
[10/05/2007|22:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/10/2005|00:36] C:\Program Files\microsoft frontpage
[28/09/2007|20:14] C:\Program Files\Microsoft Office
[04/10/2008|18:51] C:\Program Files\Microsoft Works
[28/09/2007|19:07] C:\Program Files\Microsoft.NET
[27/10/2005|00:36] C:\Program Files\Movie Maker
[17/02/2008|10:43] C:\Program Files\Mozilla Firefox
[13/03/2007|14:56] C:\Program Files\MSN
[27/10/2005|00:36] C:\Program Files\MSN Gaming Zone
[05/11/2007|22:00] C:\Program Files\MSXML 4.0
[02/01/2005|01:39] C:\Program Files\muvee Technologies
[27/10/2005|00:36] C:\Program Files\NetMeeting
[08/04/2007|17:49] C:\Program Files\Odebit Multim‚dia
[27/10/2005|00:36] C:\Program Files\Online Services
[19/02/2007|17:06] C:\Program Files\orange
[13/06/2007|15:56] C:\Program Files\Outlook Express
[15/01/2007|13:40] C:\Program Files\QuickTime
[12/02/2008|13:30] C:\Program Files\SAGEM
[01/10/2008|18:19] C:\Program Files\Samsung
[02/01/2005|01:48] C:\Program Files\Services en ligne
[30/08/2006|18:15] C:\Program Files\Smart Panel
[08/04/2007|15:01] C:\Program Files\Softwin
[28/09/2007|18:26] C:\Program Files\Sonic
[04/10/2008|12:43] C:\Program Files\Sun
[17/08/2007|22:34] C:\Program Files\Trend Micro
[20/10/2005|21:06] C:\Program Files\Uninstall Information
[24/09/2007|18:38] C:\Program Files\VideoLAN
[08/10/2008|21:36] C:\Program Files\Wanadoo
[15/01/2007|11:55] C:\Program Files\Wanadoo Messager
[05/10/2008|11:14] C:\Program Files\Windows Live
[05/10/2008|11:17] C:\Program Files\Windows Live Toolbar
[07/01/2007|15:57] C:\Program Files\Windows Media Connect 2
[05/10/2008|11:36] C:\Program Files\Windows Media Player
[27/10/2005|00:36] C:\Program Files\Windows NT
[20/10/2005|21:05] C:\Program Files\WindowsUpdate
[17/08/2007|22:19] C:\Program Files\Winsos
[27/10/2005|00:37] C:\Program Files\xerox
[04/10/2008|12:25] C:\Program Files\Yahoo!
[23/05/2007|22:31] C:\Program Files\YesMessenger
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[16/06/2008|18:51] C:\Program Files\Fichiers communs\Adobe
[12/07/2006|21:42] C:\Program Files\Fichiers communs\AOL
[28/09/2007|19:08] C:\Program Files\Fichiers communs\DESIGNER
[02/01/2005|01:19] C:\Program Files\Fichiers communs\Hewlett-Packard
[28/09/2007|18:26] C:\Program Files\Fichiers communs\InstallShield
[04/10/2008|12:40] C:\Program Files\Fichiers communs\Java
[02/01/2005|01:34] C:\Program Files\Fichiers communs\LightScribe
[06/10/2008|09:50] C:\Program Files\Fichiers communs\Microsoft Shared
[27/10/2005|00:35] C:\Program Files\Fichiers communs\MSSoap
[27/10/2005|00:35] C:\Program Files\Fichiers communs\ODBC
[28/09/2007|18:23] C:\Program Files\Fichiers communs\Real
[27/10/2005|00:35] C:\Program Files\Fichiers communs\Services
[09/04/2007|12:31] C:\Program Files\Fichiers communs\Softwin
[27/10/2005|00:35] C:\Program Files\Fichiers communs\SpeechEngines
[04/10/2008|12:24] C:\Program Files\Fichiers communs\Symantec Shared
[28/09/2007|19:08] C:\Program Files\Fichiers communs\System
[15/02/2008|12:22] C:\Program Files\Fichiers communs\WindowsLiveInstaller
--------------------\\ Process
( 38 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 21:41:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 115
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf
C:\WINDOWS\System32\qgefovdy.dat
C:\WINDOWS\System32\qgefovdy_nav.dat
C:\WINDOWS\System32\qgefovdy_navps.dat
[b]==> EGDACCESS <==/b
[HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.116.163 85.255.112.176
[b]==> WAREOUT <==/b
--------------------\\ ROGUES ..
C:\DOCUME~1\HP_PRO~1\APPLIC~1\DriveCleaner 2006 Free
[F:5][D:0]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
[F:70][D:0]-> C:\DOCUME~1\HP_PRO~1\Cookies
[F:1784][D:5]-> C:\DOCUME~1\HP_PRO~1\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 08/10/2008|21:27 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 08/10/2008|21:35 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 08/10/2008|21:42 - Option : [2]
--------------------\\ Fin du rapport a 21:42:37
OK
Refais un Hijackthis stp, qu'on voit un peu où on en est.
Refais un Hijackthis stp, qu'on voit un peu où on en est.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:46:50, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
Scan saved at 21:46:50, on 08/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.1 80.10.246.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.163 85.255.112.176
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
Télécharge Fixwareout : http://downloads.subratam.org/Fixwareout.exe
Double clique sur Fixwareout.exe
Clique "Next", puis "Install", et vérifie que "Run fixit" soit coché, puis tu cliques "Finish".
Suis les directives à l'écran.
L'outil va te demander de redémarrer ton PC, tu redémarres.
Le redémarrage risque de prendre un peu plus de temps, ceci est normal.
Le rapport sera dans le bloc note lors du redémarrage et tu pourras le sauvegarder.
Pour copier/coller le rapport du "Bloc note" tu vas dans le menu Édition et clique sur "Sélectionner tout" et retourne dans "Édition" et clique sur "copier"
Sur le forum, faire un click droit et cliquer sur "coller".
Double clique sur Fixwareout.exe
Clique "Next", puis "Install", et vérifie que "Run fixit" soit coché, puis tu cliques "Finish".
Suis les directives à l'écran.
L'outil va te demander de redémarrer ton PC, tu redémarres.
Le redémarrage risque de prendre un peu plus de temps, ceci est normal.
Le rapport sera dans le bloc note lors du redémarrage et tu pourras le sauvegarder.
Pour copier/coller le rapport du "Bloc note" tu vas dans le menu Édition et clique sur "Sélectionner tout" et retourne dans "Édition" et clique sur "copier"
Sur le forum, faire un click droit et cliquer sur "coller".
Username "HP_Propri‚taire" - 08/10/2008 21:59:07 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.163 85.255.112.176" <Value cleared.
Cache de résolution DNS vidé.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"EPSON Stylus CX3600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9BE.EXE /P26 \"EPSON Stylus CX3600 Series\" /M \"Stylus CX3600\" /EF \"HKCU\""
"ccleaner"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /AUTO"
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background"
"drv spam"="C:\\DOCUME~1\\HP_PRO~1\\APPLIC~1\\INTERN~1\\heart logo.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
~~~~~ Prerun check
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.163 85.255.112.176" <Value cleared.
Cache de résolution DNS vidé.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"EPSON Stylus CX3600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9BE.EXE /P26 \"EPSON Stylus CX3600 Series\" /M \"Stylus CX3600\" /EF \"HKCU\""
"ccleaner"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /AUTO"
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background"
"drv spam"="C:\\DOCUME~1\\HP_PRO~1\\APPLIC~1\\INTERN~1\\heart logo.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Je vais devoir en rester la pour ce soir je me reconnecterai demain pour savoir si on avais bien terminer.
Merci quand même
A demain
Merci quand même
A demain
Refais un Hijackthis stp.
bonjour,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:56, on 09/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.9 80.10.246.132
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:56, on 09/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /M "Stylus CX3600" /EF "HKCU"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?AuthParam=1223116874_0a2f2ca51ca8f469c71741077253d18b&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab&File=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{132D263C-7B0F-4B19-9416-AFE3255A1DB1}: NameServer = 81.253.149.9 80.10.246.132
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
télécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe
de Old_Timer) sur ton Bureau.
Relance HijackThis.
Clique sur Scan Only et coche la ligne suivante :
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connection Internet.
Clique sur Fix checked puis clique sur OK
Puis ferme HijackThis.
Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.
C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
http://oldtimer.geekstogo.com/OTMoveIt3.exe
de Old_Timer) sur ton Bureau.
Relance HijackThis.
Clique sur Scan Only et coche la ligne suivante :
O4 - HKCU\..\Run: [drv spam] C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connection Internet.
Clique sur Fix checked puis clique sur OK
Puis ferme HijackThis.
Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : Paste List of Files/Folders to be moved.
C:\DOCUME~1\HP_PRO~1\APPLIC~1\INTERN~1\heart logo.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
je ne trouve pas SAVE LOG pour enregistrer le rapport et le bloc note