Trop de pb sur pc (virus, redirecting...)

Bonjour,
je ne sais plus comment me débarraser de nombreux problèmes qui arrivent sur mon pc :
j'ai beau scanner, supprimer... rien à faire !
tout a commencé avec lo.st dont je pense m'être débarrassée...
mon anti virus est avast professionnel (payé 49 euros...)
les problèmes sont les suivants :
des "redirecting" avec mozilla firefox bizarrement moins galère en passant par free
des soucis pour télécharger hijack pour le rapport
une journée "écran noir bloqué"
de plus je viens de récupérer ce pc d'une société qui fermait. il est tout neuf !
si vous aviez une petite idée pour me sauver...ce serait très sympa
cordialement
virginie
Configuration: Windows XP
Firefox 3.0.3

61 réponses

Résumé de la discussion

Des problèmes variés sur un PC Windows XP, dont des redirections dans Firefox et des écrans noirs, surviennent après une infection présumée par lo.st et posent des difficultés avec Avast. Pour résoudre cela, la meilleure approche proposée est de désinstaller puis réinstaller le logiciel problématique afin de supprimer les composants malveillants et rétablir les paramètres. D'autres conseils utiles portent sur le nettoyage des éléments persistants: outils de détection, suppression de fichiers et de clés de registre associées, et la désactivation temporaire de la protection résidente pour tester les comportements. En cas de persistance, il peut être utile d’effectuer une vérification hors ligne et d’examiner les éléments de démarrage et les autoruns via des outils spécialisés, sans se fier uniquement à l’antivirus.

Bobot (l’IA à votre service)
  1. Modérateur
    Tu le désinstalles puis tu le réinstalles.
    1
    1. Modérateur
      Salut,

      - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

      - Double-clique sur RSIT.exe afin de lancer le programme.

      - Clique sur Continue à l'écran Disclaimer.

      - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

      Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
      0
      1. merci pour ta réponse
        ça donne ceci :
        info.txt logfile of random's system information tool 1.04 2008-11-08 11:56:53

        ======Uninstall list======

        -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
        -->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        4D Client-->MsiExec.exe /I{5A600E0B-FE75-44E5-A72C-D9D986A88028}
        Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
        Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 7.0.8 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
        Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
        Belkin High-Speed Mode Wireless G USB Network Adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Belkin\F5D7051\setup.exe" -l0x9
        Brother MFL-Pro Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9232446D-2BBD-11D7-946C-00E029591716}\Setup.exe" -l0x40c Brunin03.dllBrunin03.dll
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        CRI - Convention collective-->C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Bureau1\Tarifs Agence\CRI\uninstall.bat
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
        eoEngine 7.1-->"C:\Program Files\EoRezo\unins000.exe"
        FileSync-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ABB86484-38BD-4759-8F1F-1D7F661705DC}\setup.exe" -l0x40c -removeonly
        Free - Kit de connexion-->C:\Program Files\Free.fr\uninstall.exe
        Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
        High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Boot Optimizer-->C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe /uninstall
        HP DVD Play 1.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
        HP Imaging Device Functions 6.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
        iTunes-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5} /l1036
        J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate"
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office 2000 Small Business-->MsiExec.exe /I{0003040C-78E1-11D2-B60F-006097C998E7}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Works 7.0-->MsiExec.exe /I{64D114CE-4234-45C2-B60A-2B07D5A48F72}
        Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
        PaperPort 8.0 SE-->MsiExec.exe /I{AEF2D1F3-0696-11D5-8E6A-00C04F7FA234}
        PC-Doctor 5 for Windows-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
        PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
        PS2-->C:\WINDOWS\system32\ps2.exe uninstall
        Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
        Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
        QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{929408E6-D265-4174-805F-81D1D914E2A4} /l1036
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        RON Tool Mxlivemedia-->C:\WINDOWS\system32\qoajboudabyum.exe
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Sonic Express Labeler-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Sonic MyDVD Plus-->MsiExec.exe /X{21657574-BD54-48A2-9450-EB03B2C7FC29}
        Sonic RecordNow Audio-->MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        Sonic RecordNow Copy-->MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
        Sonic RecordNow Data-->MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
        Sonic Update Manager-->MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        SyncToy-->MsiExec.exe /I{E7887F0B-066C-4D26-AFD9-62B72CF24D9A}
        TightVNC 1.2.9-->"C:\Program Files\TightVNC\unins000.exe"
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        Yahoo! ¤u¨ã¦C-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
        Yahoo! Extras-->C:\PROGRA~1\Yahoo!\Common\unyext.exe
        Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
        Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll

        ======Security center information======

        AV: avast! antivirus 4.8.1229 [VPS 081107-0]

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
        "PROCESSOR_REVISION"=0409
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "SonicCentral"=c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
        "CLASSPATH"=C:\Program Files\Java\jre1.5.0_05\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.5.0_05\lib\ext\QTJava.zip

        -----------------EOF-----------------
        Logfile of random's system information tool 1.04 (written by random/random)
        Run by Compaq_Propriétaire at 2008-11-08 11:56:38
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 171 GB (93%) free of 185 GB
        Total RAM: 446 MB (5% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:56:48, on 08/11/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\CyberLink\PowerCinema\PCMService.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
        C:\Program Files\Belkin\F5D7051\WLService.exe
        C:\HP\KBD\KBD.EXE
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
        C:\WINDOWS\system32\Brmfrmps.exe
        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        C:\WINDOWS\system32\cisvc.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\WINDOWS\_aleste.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
        C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\TightVNC\WinVNC.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        c:\windows\system\hpsysdrv.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\Compaq_Propriétaire\Bureau\RSIT(2).exe
        C:\Program Files\trend micro\Compaq_Propriétaire.exe
        C:\WINDOWS\system32\cmd.exe
        C:\WINDOWS\system32\ping.exe
        C:\WINDOWS\system32\find.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: mxlivemedia browser enhancer - {E553FE3C-1AD2-86CC-D831-AF96D7DAEE8A} - C:\WINDOWS\system32\kkkplpumljqiuz.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
        O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
        O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
        O4 - HKLM\..\Run: [regcmdcons] c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
        O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
        O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
        O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmflp03\BrStDvPt.exe
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [Aleste] C:\WINDOWS\_aleste.exe
        O4 - HKLM\..\Run: [gvpwihowkksydj] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\kkkplpumljqiuz.dll"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        O4 - Global Startup: SmartUI.lnk = ?
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O17 - HKLM\System\CCS\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer = 193.252.19.3,193.252.19.4
        O17 - HKLM\System\CS1\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer = 193.252.19.3,193.252.19.4
        O17 - HKLM\System\CS2\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer = 193.252.19.3,193.252.19.4
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Belkin High-Speed Mode Wireless G USB Driver (Belkin High-Speed Mode Wireless G USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\F5D7051\WLService.exe
        O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        O23 - Service: VNC Server (winvnc) - Constantin Kaplinsky - C:\Program Files\TightVNC\WinVNC.exe
        0
        1. Modérateur
          "eoEngine 7.1-->"C:\Program Files\EoRezo\unins000.exe"
          ---> Commence par désinstaller ce programme en passant par Ajout/Suppression des programmes.
          0
          1. merci c fait mais un autre pb c que je ne peux pas désinstaller certain programmes inconnus qui me demandent une clé...
            0
            1. genre ron tool mxlivemedia qui m'embête aussi
              0
              1. Modérateur
                - Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

                /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                - Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
                - Double-clique sur l'icône Ad-remover située sur ton Bureau.
                - Au menu principal, choisis l'option "A".
                - Poste le rapport qui apparaît à la fin.

                (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

                (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

                Note :

                "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                0
                1. bon, je vais essayer de suivre tes instructions, comme je ne suis pas une lumière en informatique... mais je devrai pouvoir me débrouiller...attends 5 mn merci
                  0
                  1. voici le resultat :

                    F --------- Logfile of AD-Remover 1.0.3.0 by C_XX ---------

                    START at: 12:21:28 | 08/11/2008
                    ON: Microsoft Windows XP [version 5.1.2600] ( Windows XP )
                    OPTION: Scan
                    EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
                    USER: Compaq_Propri‚taire | PC: PC-ANNE
                    BOOT MODE: Normal
                    DRIVE(S): C:\ ~> Systemdrive: C:\

                    IE: 6.0.2900.2180

                    --------- [ PROCESSES ] ---------

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                    C:\Program Files\Belkin\F5D7051\WLService.exe
                    C:\HP\KBD\KBD.EXE
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
                    C:\WINDOWS\system32\Brmfrmps.exe
                    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                    C:\WINDOWS\system32\cisvc.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\WINDOWS\_aleste.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                    C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                    C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TightVNC\WinVNC.exe
                    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    c:\windows\system\hpsysdrv.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                    C:\WINDOWS\system32\cidaemon.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\nbtstat.exe
                    C:\WINDOWS\system32\find.exe
                    C:\WINDOWS\System32\WScript.exe

                    ---------------------------- [~> 53]

                    +---------------------------------------------------------------------------+
                    +------------------------------- SERVICES FOUND
                    +---------------------------------------------------------------------------+

                    +---------------------------------------------------------------------------+
                    +------------------------------- REGISTRY ELEMENTS FOUND
                    +---------------------------------------------------------------------------+

                    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" /v "EoEngine"
                    "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                    "HKEY_CURRENT_USER\SOFTWARE\EoRezo"
                    "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
                    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
                    "HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
                    "HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"

                    +---------------------------------------------------------------------------+
                    +------------------------------- FILES\FOLDERS FOUND
                    +---------------------------------------------------------------------------+

                    [08/11/2008 12:05|d--------] C:\Program Files\EoRezo
                    [01/11/2008 15:54|d--------] C:\Documents and Settings\Compaq_Propri‚taire\Application Data\EoRezo

                    +---------- Scanning prefs.js ... ( # Mozilla User Preferences )

                    ...\q43r7rwz.default\prefs.js :

                    Start Page : "https://www.google.com/?gws_rd=ssl"

                    +----------+

                    +---------------------------------------------------------------------------+

                    +---------- Added scan ...

                    +-----[HKLM\...\Run]

                    RTHDCPL REG_SZ RTHDCPL.EXE
                    PCMService REG_SZ "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                    Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
                    PCDrProfiler REG_SZ
                    HPBootOp REG_SZ "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                    Reminder REG_SZ "C:\Windows\Creator\Remind_XP.exe"
                    regcmdcons REG_SZ c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
                    QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    WinVNC REG_SZ "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
                    PaperPort PTD REG_SZ C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                    IndexSearch REG_SZ C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
                    SetDefPrt REG_SZ C:\Program Files\Brother\Brmflp03\BrStDvPt.exe
                    KBD REG_SZ C:\HP\KBD\KBD.EXE
                    TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
                    ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                    HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                    EoEngine REG_SZ
                    !AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    Aleste REG_SZ C:\WINDOWS\_aleste.exe
                    gvpwihowkksydj REG_SZ C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\kkkplpumljqiuz.dll"
                    avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

                    +-----[HKCU\...\Run]

                    WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                    updateMgr REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
                    swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

                    +-----[HKLM\...\Internet Explorer\MAIN]

                    Start Page : hxxp://www.google.com

                    +-----[HKCU\...\Internet Explorer\MAIN]

                    Start Page : hxxp://google.fr/

                    +---------------------------------------------------------------------------+
                    +------------------------------- [ EOF - 133 lines ]
                    +---------------------------------------------------------------------------+

                    [ END at: 12:22:02 | 08/11/2008 ] - [ Time elapsed: 33.7 seconds ]
                    0
                    1. Modérateur
                      /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                      - Clique droit sur AD-Remover et choisis Exécuter en tant qu'administrateur : au menu principal choisi l'option "B".

                      --> Le programme va travailler...

                      - Poste le rapport qui apparaît à la fin.

                      (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

                      /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
                      0
                      1. si je n'ai pas fait de bêtises, ça donne ça

                        F --------- Logfile of AD-Remover 1.0.3.0 by C_XX ---------

                        START at: 12:21:28 | 08/11/2008
                        ON: Microsoft Windows XP [version 5.1.2600] ( Windows XP )
                        OPTION: Scan
                        EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
                        USER: Compaq_Propri‚taire | PC: PC-ANNE
                        BOOT MODE: Normal
                        DRIVE(S): C:\ ~> Systemdrive: C:\

                        IE: 6.0.2900.2180

                        --------- [ PROCESSES ] ---------

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                        C:\Program Files\Belkin\F5D7051\WLService.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
                        C:\WINDOWS\system32\Brmfrmps.exe
                        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                        C:\WINDOWS\system32\cisvc.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\WINDOWS\_aleste.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                        C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\TightVNC\WinVNC.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        c:\windows\system\hpsysdrv.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                        C:\WINDOWS\system32\cidaemon.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\WINDOWS\system32\nbtstat.exe
                        C:\WINDOWS\system32\find.exe
                        C:\WINDOWS\System32\WScript.exe

                        ---------------------------- [~> 53]

                        +---------------------------------------------------------------------------+
                        +------------------------------- SERVICES FOUND
                        +---------------------------------------------------------------------------+

                        +---------------------------------------------------------------------------+
                        +------------------------------- REGISTRY ELEMENTS FOUND
                        +---------------------------------------------------------------------------+

                        "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" /v "EoEngine"
                        "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                        "HKEY_CURRENT_USER\SOFTWARE\EoRezo"
                        "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                        "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
                        "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
                        "HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
                        "HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"

                        +---------------------------------------------------------------------------+
                        +------------------------------- FILES\FOLDERS FOUND
                        +---------------------------------------------------------------------------+

                        [08/11/2008 12:05|d--------] C:\Program Files\EoRezo
                        [01/11/2008 15:54|d--------] C:\Documents and Settings\Compaq_Propri‚taire\Application Data\EoRezo

                        +---------- Scanning prefs.js ... ( # Mozilla User Preferences )

                        ...\q43r7rwz.default\prefs.js :

                        Start Page : "https://www.google.com/?gws_rd=ssl"

                        +----------+

                        +---------------------------------------------------------------------------+

                        +---------- Added scan ...

                        +-----[HKLM\...\Run]

                        RTHDCPL REG_SZ RTHDCPL.EXE
                        PCMService REG_SZ "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                        Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
                        PCDrProfiler REG_SZ
                        HPBootOp REG_SZ "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                        Reminder REG_SZ "C:\Windows\Creator\Remind_XP.exe"
                        regcmdcons REG_SZ c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
                        QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        WinVNC REG_SZ "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
                        PaperPort PTD REG_SZ C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                        IndexSearch REG_SZ C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
                        SetDefPrt REG_SZ C:\Program Files\Brother\Brmflp03\BrStDvPt.exe
                        KBD REG_SZ C:\HP\KBD\KBD.EXE
                        TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
                        ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                        HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                        EoEngine REG_SZ
                        !AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        Aleste REG_SZ C:\WINDOWS\_aleste.exe
                        gvpwihowkksydj REG_SZ C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\kkkplpumljqiuz.dll"
                        avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

                        +-----[HKCU\...\Run]

                        WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                        ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                        updateMgr REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
                        swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

                        +-----[HKLM\...\Internet Explorer\MAIN]

                        Start Page : hxxp://www.google.com

                        +-----[HKCU\...\Internet Explorer\MAIN]

                        Start Page : hxxp://google.fr/

                        +---------------------------------------------------------------------------+
                        +------------------------------- [ EOF - 133 lines ]
                        +---------------------------------------------------------------------------+

                        [ END at: 12:22:02 | 08/11/2008 ] - [ Time elapsed: 33.7 seconds ]
                        0
                        1. Modérateur
                          Ce n'est pas le bon rapport.
                          0
                          1. F --------- Logfile of AD-Remover 1.0.3.0 by C_XX ---------

                            START at: 12:34:53 | 08/11/2008
                            ON: Microsoft Windows XP [version 5.1.2600] ( Windows XP )
                            OPTION: Clean
                            EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
                            USER: Compaq_Propri‚taire | PC: PC-ANNE
                            BOOT MODE: Normal
                            DRIVE(S): C:\ ~> Systemdrive: C:\

                            IE: 6.0.2900.2180

                            --------- [ PROCESSES ] ---------

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                            C:\Program Files\Belkin\F5D7051\WLService.exe
                            C:\HP\KBD\KBD.EXE
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
                            C:\WINDOWS\system32\Brmfrmps.exe
                            C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            C:\WINDOWS\system32\cisvc.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                            C:\WINDOWS\_aleste.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                            C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\TightVNC\WinVNC.exe
                            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            c:\windows\system\hpsysdrv.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                            C:\WINDOWS\system32\cidaemon.exe
                            C:\WINDOWS\system32\notepad.exe
                            C:\WINDOWS\system32\cmd.exe
                            C:\WINDOWS\System32\WScript.exe
                            C:\WINDOWS\system32\cmd.exe
                            C:\WINDOWS\system32\ping.exe
                            C:\WINDOWS\system32\find.exe

                            ---------------------------- [~> 51]

                            +---------------------------------------------------------------------------+
                            +------------------------------- SERVICES DELETED
                            +---------------------------------------------------------------------------+

                            +---------------------------------------------------------------------------+
                            +------------------------------- REGISTRY ELEMENTS DELETED
                            +---------------------------------------------------------------------------+

                            "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" /v "EoEngine"
                            "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                            "HKEY_CURRENT_USER\SOFTWARE\EoRezo"
                            "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
                            "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
                            "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
                            "HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
                            "HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"

                            +---------------------------------------------------------------------------+
                            +------------------------------- FILES\FOLDERS DELETED
                            +---------------------------------------------------------------------------+

                            [08/11/2008 12:05|d--------] C:\Program Files\EoRezo
                            [01/11/2008 15:54|d--------] C:\Documents and Settings\Compaq_Propri‚taire\Application Data\EoRezo

                            (!) ---- Temp files deleted.

                            (!) ---- Recycle bin emptied in all drives.

                            +---------- Scanning prefs.js ... ( # Mozilla User Preferences )

                            ...\q43r7rwz.default\prefs.js :

                            Start Page : "https://www.google.com/?gws_rd=ssl"

                            +----------+

                            +---------- Added scan ...

                            +-----[HKLM\...\Run]

                            RTHDCPL REG_SZ RTHDCPL.EXE
                            PCMService REG_SZ "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                            Recguard REG_SZ C:\WINDOWS\SMINST\RECGUARD.EXE
                            PCDrProfiler REG_SZ
                            HPBootOp REG_SZ "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                            Reminder REG_SZ "C:\Windows\Creator\Remind_XP.exe"
                            regcmdcons REG_SZ c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
                            QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            WinVNC REG_SZ "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
                            PaperPort PTD REG_SZ C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                            IndexSearch REG_SZ C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
                            SetDefPrt REG_SZ C:\Program Files\Brother\Brmflp03\BrStDvPt.exe
                            KBD REG_SZ C:\HP\KBD\KBD.EXE
                            TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
                            ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                            HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            !AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                            Aleste REG_SZ C:\WINDOWS\_aleste.exe
                            gvpwihowkksydj REG_SZ C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\kkkplpumljqiuz.dll"
                            avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

                            +-----[HKCU\...\Run]

                            WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                            ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                            updateMgr REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
                            swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

                            +-----[HKLM\...\Internet Explorer\MAIN]

                            Start Page : hxxp://fr.msn.com/

                            +-----[HKCU\...\Internet Explorer\MAIN]

                            Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                            +---------------------------------------------------------------------------+
                            +------------------------------- [ EOF - 129 lines ]
                            +---------------------------------------------------------------------------+

                            [ END at: 12:37:29 | 08/11/2008 ] - [ Time elapsed: 2 minutes, 36 seconds ]
                            0
                            1. Modérateur
                              ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                              ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                              ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                              ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                              ---> Sélectionne Exécuter un examen rapide.
                              ---> Clique sur Rechercher. L'analyse démarre.

                              A la fin de l'analyse, un message s'affiche :

                              L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                              ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                              ---> Ferme tes navigateurs.
                              Si des malwares ont été détectés, clique sur Afficher les résultats.
                              ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                              ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                              0
                              1. j'avais déjà ce programme, le problème c que avant toutes ces manip il detectait des trojean mais aussi quelquefois rien ???
                                j'ai donc le resultat de "maintenant"
                                Malwarebytes' Anti-Malware 1.27
                                Version de la base de données: 1127
                                Windows 5.1.2600 Service Pack 3

                                08/11/2008 12:54:47
                                mbam-log-2008-11-08 (12-54-47).txt

                                Type de recherche: Examen rapide
                                Eléments examinés: 41862
                                Temps écoulé: 2 minute(s), 26 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 0
                                Valeur(s) du Registre infectée(s): 0
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 0
                                Fichier(s) infecté(s): 0

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Valeur(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                (Aucun élément nuisible détecté)

                                Fichier(s) infecté(s):
                                (Aucun élément nuisible détecté)
                                0
                                1. le pc est débarrassé du problème ?
                                  0
                                  1. Modérateur
                                    - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) sur ton Bureau.
                                    http://siri.urz.free.fr/Fix/SmitfraudFix.exe

                                    - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée.

                                    - Un rapport sera généré, poste-le dans ta prochaine réponse.

                                    [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

                                    ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix.
                                    0
                                    1. SmitFraudFix v2.373

                                      Rapport fait à 13:18:51,53, 08/11/2008
                                      Executé à partir de C:\Documents and Settings\Compaq_Propri‚taire\Bureau\SmitfraudFix
                                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                      Le type du système de fichiers est
                                      Fix executé en mode normal

                                      »»»»»»»»»»»»»»»»»»»»»»»» Process

                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\WINDOWS\RTHDCPL.EXE
                                      C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\Program Files\QuickTime\qttask.exe
                                      C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
                                      C:\Program Files\Belkin\F5D7051\WLService.exe
                                      C:\HP\KBD\KBD.EXE
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                      C:\Program Files\Belkin\F5D7051\WLanCfgG.exe
                                      C:\WINDOWS\system32\Brmfrmps.exe
                                      C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                      C:\WINDOWS\system32\cisvc.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\WINDOWS\_aleste.exe
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                                      C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\TightVNC\WinVNC.exe
                                      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                                      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      c:\windows\system\hpsysdrv.exe
                                      C:\Program Files\iTunes\iTunesHelper.exe
                                      C:\Program Files\iPod\bin\iPodService.exe
                                      C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
                                      C:\WINDOWS\system32\cidaemon.exe
                                      C:\WINDOWS\explorer.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\WINDOWS\system32\cmd.exe
                                      C:\WINDOWS\system32\cmd.exe
                                      C:\WINDOWS\system32\ping.exe
                                      C:\WINDOWS\system32\find.exe

                                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Propri‚taire

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Propri‚taire\Application Data

                                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\Favoris

                                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                      "Source"="About:Home"
                                      "SubscribedURL"="About:Home"
                                      "FriendlyName"="Ma page d'accueil"

                                      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      o4Patch
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      IEDFix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      VACFix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      404Fix
                                      Credits: Malware Analysis & Diagnostic
                                      Code: S!Ri

                                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      SrchSTS.exe by S!Ri
                                      Search SharedTaskScheduler's .dll

                                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                      "AppInit_DLLs"=""

                                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                                      "System"=""

                                      »»»»»»»»»»»»»»»»»»»»»»»» RK

                                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
                                      DNS Server Search Order: 15.243.128.51
                                      DNS Server Search Order: 15.243.160.51

                                      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
                                      DNS Server Search Order: 212.27.40.241
                                      DNS Server Search Order: 212.27.40.240

                                      Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
                                      DNS Server Search Order: 193.252.19.3
                                      DNS Server Search Order: 193.252.19.4

                                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer=193.252.19.3,193.252.19.4
                                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{ACE88AD7-8681-4E08-A558-DF2714C95F2C}: DhcpNameServer=212.27.40.241 212.27.40.240
                                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer=193.252.19.3,193.252.19.4
                                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{ACE88AD7-8681-4E08-A558-DF2714C95F2C}: DhcpNameServer=212.27.40.241 212.27.40.240
                                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{5F226889-7081-4DF7-882B-25A3E3092DB6}: NameServer=193.252.19.3,193.252.19.4
                                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{ACE88AD7-8681-4E08-A558-DF2714C95F2C}: DhcpNameServer=212.27.40.241 212.27.40.240
                                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240
                                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

                                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                      »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                      0
                                      1. Modérateur
                                        ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                                        http://oldtimer.geekstogo.com/OTMoveIt3.exe

                                        ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                                        ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                                        :processes
                                        explorer.exe

                                        :files
                                        C:\WINDOWS\_aleste.exe
                                        C:\WINDOWS\system32\kkkplpumljqiuz.dll
                                        C:\Program Files\EoRezo
                                        C:\WINDOWS\system32\qoajboudabyum.exe
                                        C:\Documents and Settings\Compaq_Propriétaire\Application Data\EoRezo

                                        :reg
                                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E553FE3C-1AD2-86CC-D831-AF96D7DAEE8A}]
                                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                        "EoEngine"=-
                                        "Aleste"=-
                                        "gvpwihowkksydj"=-
                                        [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2de0b33e-0ffc-11db-a525-001150c37652}]

                                        :commands
                                        [emptytemp]
                                        [start explorer]
                                        [reboot]

                                        ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                                        ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                                        Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                        Accepte en cliquant sur YES.

                                        ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                                        Le nom du rapport correspond au moment de sa création : date_heure.log
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4