VIRUS - Page 2

Précédent
  • 1
  • 2
  • 3
  1. E..T Messages postés 6565 Statut Contributeur 437
     
    ça ne marche pas... Tu ne pas faire de restauration à une heure antérieur?
    1
  2. E..T Messages postés 6565 Statut Contributeur 437
     
    Ouep,
    C'est quoi la marque de ton pc?

    Essaye ça:
    * Démarre en mode sans échec
    Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
    Redémarres l’ordinateur
    Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
    Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.

    Ouvres OTMoveIt .

    -> cliques sur le bouton [restor]

    --> dans la fenêtre qui s'ouvre : sélectionne le fichier " xxxx2008_xxxxxx.res " ( les " x " sont des chiffres ) et cliques sur " ouvrir " .

    --> dans cette nouvelle fenêtre d'OTmoveIt qui vient d'apparaitre, sélectionnes TOUTES les lignes présentes et cliques sur [RestorIt] .

    -> redémarres le PC et retestes ....

    ++
    1
  3. Bob_74 Messages postés 48 Statut Membre
     
    ok j'essaie tout de suite
    0
  4. Bob_74 Messages postés 48 Statut Membre
     
    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1275
    Windows 5.1.2600 Service Pack 2

    16/10/2008 16:25:02
    mbam-log-2008-10-16 (16-25-02).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 174526
    Temps écoulé: 21 minute(s), 38 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Bob_74 Messages postés 48 Statut Membre
     
    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1275
    Windows 5.1.2600 Service Pack 2

    16/10/2008 16:25:02
    mbam-log-2008-10-16 (16-25-02).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 174526
    Temps écoulé: 21 minute(s), 38 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    et voilà c'est fait...
    0
  7. Bob_74 Messages postés 48 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:14:44, on 17/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WinZip\WZQKPICK.EXE
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\eMule\Incoming\eMule\emule.exe
    C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O16 - DPF: microsoft xml parser for java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Service Bonjour (bonjour service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (ipod service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
    O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    0
  8. Bob_74 Messages postés 48 Statut Membre
     
    Salut E..T

    Voici le rapport...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:41:29, on 20/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O16 - DPF: microsoft xml parser for java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Service Bonjour (bonjour service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (ipod service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
    O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    0
  9. E..T Messages postés 6565 Statut Contributeur 437
     
    Hello,

    Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
    double-clique sur OTMoveIt.exe pour le lancer.
    Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
    copie la liste qui se trouve en gras ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    @++
    0
  10. Bob_74 Messages postés 48 Statut Membre
     
    All ,ready done...

    Il ne m'à pas demander de redémarer.

    Voici le rapport :

    File/Folder C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1 not found.

    OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10202008_185650
    0
  11. Bob_74 Messages postés 48 Statut Membre
     
    Infection absente


    Pas de fichiers types date_heures_.txt



    Dossier .txt :


    C:\Program Files\skmw\
    C:\Program Files\skmw\sec\
    C:\Program Files\skmw\WinRds\
    C:\Program Files\Microsoft Studio Files\
    C:\Program Files\nsnimage\
    C:\Program Files\RealtekAZ\
    C:\Program Files\xerox\nwmedia\
    C:\WINDOWS\system32\mrdv\
    C:\Program Files\Spcron\
    C:\Program Files\Svconr\
    C:\DOCUME~1\HP_PRO~1\APPLIC~1\WinTouch\
    C:\Program Files\CPV\
    C:\Program Files\nvcoi\
    C:\Program Files\outerinfo\
    C:\Program Files\Temporary\
    C:\DOCUME~1\HP_PRO~1\APPLIC~1\SpeedRunner\
    C:\Program Files\Twain\
    C:\Program Files\Inet_Get_2\
    C:\Program Files\Fichiers communs\Carlson\
    C:\Program Files\Fichiers communs\Delsim\
    \Carlson\
    C:\Program Files\Bifrost\
    C:\Program Files\ddm\
    C:\Program Files\InetGet2\
    C:\Program Files\Insider\
    C:\Program Files\ISM\
    C:\Program Files\ISM2\
    C:\Program Files\QdrModule\
    C:\Program Files\QdrPack\
    C:\Program Files\Temporary\
    C:\Program Files\WinAble\
    C:\Program Files\WinPop\
    C:\Program Files\nvcoi\
    C:\AVG_BETA\
    C:\Conf\
    C:\Install\
    C:\Lixo\
    C:\oddysee\
    C:\Program Files\nvcoi\
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\ARC64\
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsa2.tmp\
    C:\WINDOWS\_tmp\
    C:\Program Files\CPV\
    C:\WINDOWS\crack\
    C:\WINDOWS\htmCache\
    C:\WINDOWS\system32\B1\
    C:\WINDOWS\system32\B2\
    C:\WINDOWS\system32\openfile\
    C:\WINDOWS\system32\Security\
    C:\WINDOWS\system32\service\
    C:\WINDOWS\system32\updatelinkmsn\
    C:\DOCUME~1\HP_PRO~1\APPLIC~1\WinTouch\
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsb2.tmp\

    Temp.txt

    [C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
    [C:\WINDOWS\system32\WinFXDocObj.exe] F248619BCAF7EA3AF6C6A7D4F1EA5699
    [C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
    [C:\WINDOWS\system32\winlogon.exe] D2DE785AEAB0BB8CA4C14A8A199DBE4E
    [C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
    [C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
    [C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
    [C:\WINDOWS\system32\winver.exe] CE30DCEF79B94D17A8B3BEC26FEF90A3
    [C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
    [C:\WINDOWS\system32\WinFXDocObj.exe] F248619BCAF7EA3AF6C6A7D4F1EA5699
    [C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
    [C:\WINDOWS\system32\winlogon.exe] D2DE785AEAB0BB8CA4C14A8A199DBE4E
    [C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
    [C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
    [C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
    [C:\WINDOWS\system32\winver.exe] CE30DCEF79B94D17A8B3BEC26FEF90A3
    0
  12. E..T Messages postés 6565 Statut Contributeur 437
     
    double-clique sur OTMoveIt.exe pour le lancer.
    Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
    copie la liste qui se trouve en gras ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    C:\DOCUME~1\HP_PRO~1\LOCALS~1

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    @++
    0
  13. Bob_74 Messages postés 48 Statut Membre
     
    l'ordinateur c'est bien éteint, en se rallumant il m'a bien affiché un rapport du type date_heure.txt

    Le voici :

    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\~DEST moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\plugtmp moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsv28.tmp moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5\MSHist012008102020081021 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB\AV3GM6XN.WNY\manifests moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB\AV3GM6XN.WNY moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000} moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\{31519424-2560-4CEF-99E8-8CC7FABA1E09} moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Paint.NET\1103296784 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Paint.NET moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\NOS moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\OfflineCache moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\Cache scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox\updates moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\User Templates moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\TEMPLATE moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\DesignGallery moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68} moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\9.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\11.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\10.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Portable Devices moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Outlook moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money\15.0\Webcache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money\15.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Transcoded Files Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Cache d’images\LocalMLS moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Cache d’images moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Services moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery\Last Active moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery\Active moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\HelpCtr moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\FORMS\IPM.Contact.SBE moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\FORMS moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\VMQLGABL moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\R3FC0X9H moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\4SPUA3HW moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\2YAQIZL7 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebFilters~ moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~ moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\Microsoft Feeds~ moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials\S-1-5-21-816502443-3659147561-3435239684-1008 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\CD Burning moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xn2hptfmkme5wqehe3foutonjsxkvjd0\AssemFiles moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xn2hptfmkme5wqehe3foutonjsxkvjd0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xitmqsrqvpqpovqi5kx5u3ghwej4ru23\AssemFiles moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xitmqsrqvpqpovqi5kx5u3ghwej4ru23 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834}\Microsoft\Outlook Express moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834}\Microsoft moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834} moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\Vault\temp moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\Vault moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\PlugInData moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\db scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\cache moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Help moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\models moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\images moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\icons moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons\Overrides moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons\Enterprise moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Conduit moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\ApplicationHistory scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier\SyncNotifier\Logs moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier\SyncNotifier moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\Safari\History moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\Safari moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\QuickTime\downloads moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\QuickTime moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\iTunes moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple\Apple Software Update moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Install\reader8rdr-fr_FR moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Install moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Data moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\ESD moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Color moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Updater moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Cache\Search80 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0\Cache\Search70 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0\Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0\Cache\Search moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0\Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1 scheduled to be moved on reboot.

    OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10202008_224829

    Files moved on Reboot...
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\SUPA983I moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\QI2LCXX9 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\BOZA6HAW moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\1CB40VT3 moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5\MSHist012008102020081021 moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\Cache moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials\S-1-5-21-816502443-3659147561-3435239684-1008 moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\db moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP moved successfully.
    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\ApplicationHistory moved successfully.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
    Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1 scheduled to be moved on reboot.
    0
  14. Bob_74 Messages postés 48 Statut Membre
     
    voici le nouveau rapport hijack. le pc va plutôt bien pas de problème récurant

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:40:03, on 21/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WinZip\WZQKPICK.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O16 - DPF: microsoft xml parser for java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Service Bonjour (bonjour service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (ipod service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
    O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    0
  15. E..T Messages postés 6565 Statut Contributeur 437
     
    Bob_74 je ne sais pas comment faire pour virer cette m****, donc moi je stop la ;-)
    On a bien avancé il reste plus grand chose donc on va pas tout casser.
    Si tu n'as pas de réponse >> Lis ceci.
    Voili voilou Désolé de na pas pouvoir finir.
    Je suis ton soucis de près ;))
    @++
    0
  16. Cesel45 Messages postés 13762 Date d'inscription   Statut Contributeur Dernière intervention   2 845
     
    Bonjour

    tu fais la même opération mais en mode sans echec..

    -1
  17. E..T Messages postés 6565 Statut Contributeur 437
     
    Bonsoir tout le monde,

    Bob_74 ça ne sert à rien de poster plusieurs foi le même message.
    1 problème >> 1 message >> Explications.

    Sur ce bon nettoyage :)

    Et sinon pour voir si tu as un virus fais ce qui suit:

    Télécharge sur le Bureau HijackThis
    Clique sur ce lien http://www.trendsecure.com/portal/en-US/threat_analyticsHJT­Install.exe

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJT.exe pour lancer le programme

    Accepte en cliquant sur le bouton "I Accept"

    Ensuite clique sur "do a system scan and save a logfile" et postes le rapport obtenu ici.

    @++
    -1
  18. Bob_74 Messages postés 48 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:45:44, on 16/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WinZip\WZQKPICK.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\eMule\Incoming\eMule\emule.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
    O16 - DPF: microsoft xml parser for java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Service Bonjour (bonjour service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
    O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
    O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
    -1
  19. E..T Messages postés 6565 Statut Contributeur 437
     
    On va faire un coup de nettoyage
    Fais ce qui suit :

    * Télécharge MalwareByte's Anti-Malware (by RubbeR DuckY) :
    *http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
    * Installe le programme sur le bureau :
    S'il te manque "COMCTL32.OCX" lors de l'installation, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/

    * Fais les mises à jour (clic sur Mises à jour puis Recherche de mises à jour)

    * Démarre en mode sans échec
    Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
    Redémarres l’ordinateur
    Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
    Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.

    * Lance MalwareByte's Anti-Malware, clique sur Exécuter un examen complet puis Rechercher et sélectionnez tous tes disques durs

    * // !! \\ Une fois le scan terminé, Si des éléments on été trouvés > cliques sur supprimer la sélection. (si un message te demande de redémarrer le PC, accepte.)

    * Un rapport sera généré, poste le ici.

    @++
    -1
  20. Bob_74 Messages postés 48 Statut Membre
     
    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1274
    Windows 5.1.2600 Service Pack 2

    16/10/2008 01:31:54
    mbam-log-2008-10-16 (01-31-54).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 178535
    Temps écoulé: 23 minute(s), 13 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 1
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 2

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550p (Rootkit.Agent) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S5EB4XYR\uaqrta[1].jpg (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drivers\asc3550p.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    -1
  21. E..T Messages postés 6565 Statut Contributeur 437
     
    Poste un rapport hijackthis.
    A bientôt.
    ++
    -1
Précédent
  • 1
  • 2
  • 3