Probleme avec "AdWare.Win32.Agent"

Bonjour,
Je suis bien embêtée avec ce truc, que j'essaie d'oter sans succès. J'ai trouvé diverses solutions sur ce site, mais le soucis est que je n'ai même plus de connection internet.
J'ai essayé une restauration du pc, il me dit bien qu'il l'a trouvé, mais veut rien faire d'autre, lui =/
Et moi, comme je suis une brêle en informatique, bah j'ai rien d'autre à faire qu'à pleurer =)
Quelqu'un aurait-il la gentillesse de m'aider, s'il vous plaît ?
En vous remerciant par avance,
Val.
Configuration: Windows Vista
Internet Explorer 7.0

198 réponses

Résumé de la discussion

Une utilisatrice sous Windows Vista et Internet Explorer 7 signale une infection persistante accompagnée d’une perte totale de connexion internet, après une restauration système qui ne donne aucun résultat. Plusieurs conseils s’articulent autour de l’analyse des rapports avec HijackThis et de l’usage d’AD-Remover, dont le rapport final est sauvegardé sur C:\Ad-report(date).log. Il est proposé de désactiver temporairement le contrôle des comptes utilisateurs et de noter que l’outil Process.exe peut être signalé par certains antivirus comme RiskTool sans être un virus. Des éléments infectieux évoqués incluent des toolbars Navipromo et des composants MSN, et des corrections de lien ont permis d’accéder à des ressources utiles pour poursuivre le dépannage.

Bobot (l’IA à votre service)
  1. Bon Marie ,nous a bloqué l'autre topic,pensant que c'etait le meme ordinateur.Donc j'ai demandé a redebloquer l'autre topic,sinon on va tout melanger.Supprimes proprement les protection orange comme indiqué pour l'ordinateur precedent,si tu te rappelle de la procedure que je t'avais donné pour le premier ordinateur
    0
    1. Salut phil,

      Tu as encore l'antivirus et le firewall orange,peux tu le supprimer selon la procedure que j'avais donné pour l'autre ordinateur car sinon source de conflit et de bugs avec avira et pc tools frewal plus
      0
      1. Recrée une page pour le suivant,et, postes un rapport hijack this en meme temps ,ca sera deja cela de fait
        0
        1. Ah comme quoi les gens du sud,contrairement à l'image vehiculé ne sont pas des mauvais bougre!!On est tous les deux du sud avec genhackman
          0
          1. vive le sud !
            lol
            0
        2. Par contre phil,comme indiqué precedemment,il serait bon de faire un controle sur les autres ordinateurs car vu le nombre d'infection sur celui ci,et vu que tu as les memes protections sur les autres(c'est à dire pas grand chose),on peut penser que tu dois avoir aussi quelques m......ouilles.

          Si tu te sens ,apres avoir terminé avec celui la,recrée un topic pour l'autre,on fera des controles.
          0
          1. ok !
            je recréé une page
            0
        3. Si genhackman pense que c'est ok ,on peut etre rassuré.Je sais plus si on avait fait la procedure de fin de desinfection?

          Je te laisse l'envoyer genhacman,j'ai vu que tu avais reactualisé quelques elements sur ta procedure,j'en profiterais pour remettre a jour l'ancienne que je t'avais honteusement piquée!!!!!!
          0
          1. ben merci beaucoup beaucoup à vos deux, les amis !

            qu"est ce que je peux faire pour vous ?

            z êtes super sympa !!!!
            0
        4. Bob ben j'avais pas trop mal travaillé alors.Il a fallut du temps
          0
          1. la classe, Lolo !
            va etre contente, Val !
            0
        5. pas grave

          pour moi tu n'as plus rien bien que ceci me posee petit souci :

          HijackThis download failed

          tu as acces normalement a tous tes sites habituels ?
          0
          1. ben j ai pas trop essayé !
            je peux aller sur le site ou nous nous trouvons, deja.
            j en essaie d autres
            0
          2. ben écoutes, ça à l'air de fonctionner plutôt bien !!!

            yeah !!!!!
            0
        6. apparemment y a plus rien mais plus de precisions ne seront pas du luxe :

          Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

          -> http://images.malwareremoval.com/random/RSIT.exe

          ! Déconnecte toi et ferme toutes tes applications en cours !

          Double-clique sur " RSIT.exe " pour le lancer .

          -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

          * Devant l'option "List files/folders created ..." , tu choisis : 2 months

          * clique ensuite sur " Continue " pour lancer l'analyse ...

          -> laisse faire le scan et ne touche pas au PC ...

          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

          Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

          Important : poste un rapport, puis l'autre dans la réponse suivante
          Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

          ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

          0
          1. ok, c'est parti !
            1er rapport !
            0
          2. Logfile of random's system information tool 1.05 (written by random/random)
            Run by Utilisateur at 2009-02-09 09:29:12
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
            System drive C: has 50 GB (36%) free of 140 GB
            Total RAM: 2046 MB (64% free)

            HijackThis download failed

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
            &Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
            Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
            Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-07 320920]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
            Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-07 34816]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
            SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-03-11 159744]
            "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-07-25 174616]
            "QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-09-30 181544]
            "QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-09-19 202032]
            "OnScreenDisplay"=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [2007-09-04 554320]
            "UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-08-16 218408]
            "DpAgent"=C:\Program Files\DigitalPersona\Bin\dpagent.exe [2007-09-20 671744]
            "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
            "HP Health Check Scheduler"=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe []
            "HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
            "hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-09-13 480560]
            "WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2007-01-08 311296]
            "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-07 136600]
            "SystrayORAHSS"=C:\Program Files\Orange\Systray\SystrayApp.exe [2007-09-25 94208]
            "ORAHSSSessionManager"=C:\Program Files\Orange\SessionManager\SessionManager.exe [2007-09-25 102400]
            "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
            "NvSvc"=C:\Windows\system32\nvsvc.dll [2007-09-19 86016]
            "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-09-19 8497696]
            "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-09-19 81920]
            "avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
            "LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2007-08-23 455968]
            "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
            "SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-01-15 1830128]

            C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
            OneNote 2007 - Capture d'écran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
            C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
            "notification packages"=scecli
            DPPWDFLT

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "DisableTaskMgr"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1
            "FilterAdministratorToken"=1
            "EnableUIADesktopToggle"=0
            "EnableLUA"=0

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NofolderOptions"=0
            "NoFind"=0
            "NoRun"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=
            "NoFolderOptions"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "C:\Program Files\Orange\Connectivity\ConnectivityManager.exe"="C:\Program Files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9af472c-ebe3-11dd-b9bd-001cbf7b808a}]
            shell\AutoRun\command - G:\LaunchU3.exe -a

            ======List of files/folders created in the last 2 months======

            2009-02-02 16:06:58 ----D---- C:\Program Files\trend micro
            2009-02-02 16:06:57 ----D---- C:\rsit
            2009-02-02 15:57:01 ----A---- C:\TCleaner.txt
            2009-02-02 15:52:52 ----D---- C:\Windows\Temp
            2009-02-02 14:20:47 ----D---- C:\Users\Utilisateur\AppData\Roaming\Yahoo!
            2009-02-02 14:20:47 ----D---- C:\ProgramData\Yahoo! Companion
            2009-02-02 14:20:46 ----D---- C:\Program Files\Yahoo!
            2009-01-31 16:26:22 ----D---- C:\Program Files\CCleaner
            2009-01-31 16:14:49 ----A---- C:\PureRa.txt
            2009-01-30 23:06:48 ----D---- C:\nup
            2009-01-30 01:19:22 ----A---- C:\resultat_clean.txt
            2009-01-28 22:32:52 ----D---- C:\Program Files\SkanerOnline
            2009-01-26 22:31:57 ----D---- C:\ProgramData\SUPERAntiSpyware.com
            2009-01-26 22:31:29 ----D---- C:\Users\Utilisateur\AppData\Roaming\SUPERAntiSpyware.com
            2009-01-26 22:31:29 ----D---- C:\Program Files\SUPERAntiSpyware
            2009-01-26 22:30:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
            2009-01-26 22:25:44 ----D---- C:\ProgramData\Avira
            2009-01-26 22:25:44 ----D---- C:\Program Files\Avira
            2009-01-26 21:22:35 ----D---- C:\Users\Utilisateur\AppData\Roaming\Malwarebytes
            2009-01-26 21:22:26 ----D---- C:\ProgramData\Malwarebytes
            2009-01-26 21:22:26 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
            2009-01-18 06:42:30 ----A---- C:\Windows\system32\msshooks.dll
            2009-01-18 06:42:22 ----A---- C:\Windows\system32\msscb.dll
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\SearchFilterHost.exe
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\propdefs.dll
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\msstrc.dll
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\mssprxy.dll
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\mssitlb.dll
            2009-01-18 06:42:15 ----A---- C:\Windows\system32\msshsq.dll
            2009-01-18 06:42:14 ----A---- C:\Windows\system32\thawbrkr.dll
            2009-01-18 06:42:14 ----A---- C:\Windows\system32\srchadmin.dll
            2009-01-18 06:42:14 ----A---- C:\Windows\system32\propsys.dll
            2009-01-18 06:42:14 ----A---- C:\Windows\system32\korwbrkr.dll
            2009-01-18 06:42:13 ----A---- C:\Windows\system32\wsepno.dll
            2009-01-18 06:42:13 ----A---- C:\Windows\system32\rtffilt.dll
            2009-01-18 06:42:13 ----A---- C:\Windows\system32\mimefilt.dll
            2009-01-18 06:42:12 ----A---- C:\Windows\system32\xmlfilter.dll
            2009-01-18 06:42:12 ----A---- C:\Windows\system32\offfilt.dll
            2009-01-18 06:42:12 ----A---- C:\Windows\system32\nlhtml.dll
            2009-01-18 06:42:11 ----A---- C:\Windows\system32\msscntrs.dll
            2009-01-18 06:42:11 ----A---- C:\Windows\system32\chsbrkr.dll
            2009-01-18 06:42:10 ----A---- C:\Windows\system32\SearchProtocolHost.exe
            2009-01-18 06:42:10 ----A---- C:\Windows\system32\chtbrkr.dll
            2009-01-18 06:42:09 ----A---- C:\Windows\system32\SearchIndexer.exe
            2009-01-18 06:42:06 ----A---- C:\Windows\system32\tquery.dll
            2009-01-18 06:42:04 ----A---- C:\Windows\system32\mssrch.dll
            2009-01-18 06:42:02 ----A---- C:\Windows\system32\mssvp.dll
            2009-01-18 06:42:01 ----A---- C:\Windows\system32\mssph.dll
            2009-01-18 06:41:58 ----A---- C:\Windows\system32\mssphtb.dll
            2009-01-18 06:05:30 ----A---- C:\Windows\system32\emdmgmt.dll
            2009-01-18 06:05:29 ----A---- C:\Windows\system32\dataclen.dll
            2009-01-18 06:05:29 ----A---- C:\Windows\system32\cdd.dll
            2009-01-18 06:05:26 ----A---- C:\Windows\system32\wersvc.dll
            2009-01-18 06:05:26 ----A---- C:\Windows\system32\Faultrep.dll
            2009-01-18 06:05:23 ----A---- C:\Windows\system32\rpcrt4.dll
            2009-01-18 06:05:16 ----A---- C:\Windows\system32\pacerprf.dll
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\wshext.dll
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\wscript.exe
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\vbscript.dll
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\scrobj.dll
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\jscript.dll
            2009-01-18 06:05:13 ----A---- C:\Windows\system32\cscript.exe
            2009-01-18 06:05:12 ----A---- C:\Windows\system32\scrrun.dll
            2009-01-18 01:03:40 ----D---- C:\PerfLogs
            2009-01-01 22:47:08 ----D---- C:\Program Files\Common Files\Adobe
            2009-01-01 22:47:08 ----D---- C:\Program Files\Adobe
            2008-12-19 08:30:49 ----D---- C:\Users\Utilisateur\AppData\Roaming\CVitae
            2008-12-19 08:30:48 ----D---- C:\Program Files\MonProduit
            2008-12-19 03:00:33 ----A---- C:\Windows\system32\mshtml.dll
            2008-12-18 23:33:56 ----D---- C:\Program Files\MSN Messenger
            2008-12-18 08:51:27 ----D---- C:\Program Files\Microsoft Silverlight
            2008-12-18 08:51:07 ----DC---- C:\Windows\system32\DRVSTORE
            2008-12-18 08:48:22 ----A---- C:\Windows\system32\d3dx9_32.dll
            2008-12-18 08:44:47 ----D---- C:\Program Files\Microsoft
            2008-12-18 08:43:58 ----D---- C:\Program Files\Windows Live SkyDrive
            2008-12-18 07:51:33 ----D---- C:\Program Files\Common Files\Windows Live
            2008-12-11 03:04:51 ----A---- C:\Windows\system32\tzres.dll
            2008-12-10 20:28:47 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
            2008-12-10 20:28:00 ----A---- C:\Windows\system32\Apphlpdm.dll
            2008-12-10 12:18:46 ----A---- C:\Windows\system32\WMVCORE.DLL
            2008-12-10 12:18:45 ----A---- C:\Windows\system32\mf.dll
            2008-12-10 12:18:41 ----A---- C:\Windows\system32\WMNetMgr.dll
            2008-12-10 12:18:41 ----A---- C:\Windows\system32\rrinstaller.exe
            2008-12-10 12:18:40 ----A---- C:\Windows\system32\mfps.dll
            2008-12-10 12:18:40 ----A---- C:\Windows\system32\logagent.exe
            2008-12-10 12:18:39 ----A---- C:\Windows\system32\mfpmp.exe
            2008-12-10 12:12:19 ----A---- C:\Windows\system32\urlmon.dll
            2008-12-10 12:12:17 ----A---- C:\Windows\system32\ieframe.dll
            2008-12-10 12:12:15 ----A---- C:\Windows\system32\wininet.dll
            2008-12-10 12:12:14 ----A---- C:\Windows\system32\mstime.dll
            2008-12-10 12:12:11 ----A---- C:\Windows\system32\iertutil.dll
            2008-12-10 12:12:08 ----A---- C:\Windows\system32\jsproxy.dll
            2008-12-10 12:00:06 ----A---- C:\Windows\system32\gdi32.dll
            2008-12-10 11:46:32 ----A---- C:\Windows\system32\shell32.dll
            2008-12-10 11:46:01 ----A---- C:\Windows\explorer.exe

            ======List of files/folders modified in the last 2 months======

            2009-02-09 08:59:12 ----D---- C:\Windows\System32
            2009-02-09 08:59:12 ----D---- C:\Windows\inf
            2009-02-09 08:59:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
            2009-02-09 08:53:05 ----RD---- C:\Program Files
            2009-02-09 08:47:43 ----SHD---- C:\System Volume Information
            2009-02-02 15:56:49 ----D---- C:\WINDOWS
            2009-02-02 15:23:40 ----SD---- C:\Windows\Downloaded Program Files
            2009-02-02 14:20:47 ----HD---- C:\ProgramData
            2009-02-01 16:46:10 ----D---- C:\Windows\system32\catroot2
            2009-02-01 13:56:31 ----D---- C:\ProgramData\F-Secure
            2009-02-01 13:56:13 ----D---- C:\Windows\system32\drivers
            2009-02-01 13:40:54 ----D---- C:\Windows\system32\LogFiles
            2009-01-31 16:29:41 ----D---- C:\Windows\Debug
            2009-01-31 16:29:40 ----D---- C:\Windows\Minidump
            2009-01-31 16:16:22 ----RSD---- C:\Windows\Media
            2009-01-31 16:16:22 ----RSD---- C:\Windows\Fonts
            2009-01-31 16:16:22 ----RD---- C:\Users
            2009-01-30 22:25:58 ----D---- C:\Program Files\HP Games
            2009-01-28 20:02:37 ----D---- C:\Windows\Prefetch
            2009-01-27 20:50:26 ----D---- C:\Windows\system32\Tasks
            2009-01-26 22:31:43 ----SHD---- C:\Windows\Installer
            2009-01-26 22:30:34 ----D---- C:\Program Files\Common Files
            2009-01-26 21:45:31 ----D---- C:\ProgramData\NVIDIA
            2009-01-24 21:44:50 ----D---- C:\Windows\winsxs
            2009-01-24 19:30:26 ----D---- C:\Windows\system32\WDI
            2009-01-24 18:48:07 ----D---- C:\Program Files\WinamaxPoker
            2009-01-18 07:11:13 ----D---- C:\Windows\rescache
            2009-01-18 06:45:09 ----D---- C:\Windows\system32\fr-FR
            2009-01-18 06:45:09 ----D---- C:\Windows\PolicyDefinitions
            2009-01-18 06:43:47 ----D---- C:\Windows\system32\catroot
            2009-01-18 02:00:20 ----D---- C:\Windows\Logs
            2009-01-18 01:28:24 ----D---- C:\Windows\Microsoft.NET
            2009-01-18 01:28:19 ----RSD---- C:\Windows\assembly
            2009-01-18 01:17:55 ----SHD---- C:\boot
            2009-01-18 01:08:16 ----D---- C:\Program Files\Windows Sidebar
            2009-01-18 01:08:16 ----D---- C:\Program Files\Windows Calendar
            2009-01-18 01:08:16 ----D---- C:\Program Files\Movie Maker
            2009-01-18 01:08:15 ----D---- C:\Program Files\Windows Media Player
            2009-01-18 01:08:15 ----D---- C:\Program Files\Windows Mail
            2009-01-18 01:08:15 ----D---- C:\Program Files\Windows Journal
            2009-01-18 01:08:15 ----D---- C:\Program Files\Windows Collaboration
            2009-01-18 01:08:15 ----D---- C:\Program Files\Internet Explorer
            2009-01-18 01:08:14 ----D---- C:\Program Files\Windows Photo Gallery
            2009-01-18 01:08:11 ----D---- C:\Program Files\Windows Defender
            2009-01-18 01:08:11 ----D---- C:\Program Files\Common Files\System
            2009-01-18 01:08:10 ----D---- C:\Windows\servicing
            2009-01-18 01:08:09 ----D---- C:\Windows\ehome
            2009-01-18 01:07:59 ----D---- C:\Windows\MSAgent
            2009-01-18 01:07:58 ----D---- C:\Windows\L2Schemas
            2009-01-18 01:07:58 ----D---- C:\Windows\IME
            2009-01-18 01:07:58 ----D---- C:\Windows\DigitalLocker
            2009-01-18 01:07:56 ----D---- C:\Windows\system32\XPSViewer
            2009-01-18 01:07:56 ----D---- C:\Windows\system32\ko-KR
            2009-01-18 01:07:56 ----D---- C:\Windows\system32\da-DK
            2009-01-18 01:07:56 ----D---- C:\Windows\system32\com
            2009-01-18 01:07:55 ----D---- C:\Windows\system32\it-IT
            2009-01-18 01:07:55 ----D---- C:\Windows\system32\en-US
            2009-01-18 01:07:55 ----D---- C:\Windows\system32\de-DE
            2009-01-18 01:07:54 ----D---- C:\Windows\system32\sysprep
            2009-01-18 01:07:54 ----D---- C:\Windows\system32\oobe
            2009-01-18 01:07:54 ----D---- C:\Windows\system32\migration
            2009-01-18 01:07:54 ----D---- C:\Windows\system32\fr
            2009-01-18 01:07:54 ----D---- C:\Windows\system32\el-GR
            2009-01-18 01:07:50 ----D---- C:\Windows\system32\ru-RU
            2009-01-18 01:07:50 ----D---- C:\Windows\system32\ias
            2009-01-18 01:07:50 ----D---- C:\Windows\system32\AdvancedInstallers
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\sv-SE
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\SLUI
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\setup
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\pt-PT
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\hu-HU
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\he-IL
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\fi-FI
            2009-01-18 01:07:40 ----D---- C:\Windows\system32\cs-CZ
            2009-01-18 01:07:36 ----D---- C:\Windows\system32\zh-CN
            2009-01-18 01:07:36 ----D---- C:\Windows\system32\manifeststore
            2009-01-18 01:07:36 ----D---- C:\Windows\system32\es-ES
            2009-01-18 01:07:35 ----D---- C:\Windows\system32\zh-TW
            2009-01-18 01:07:35 ----D---- C:\Windows\system32\ro-RO
            2009-01-18 01:07:35 ----D---- C:\Windows\system32\pl-PL
            2009-01-18 01:07:35 ----D---- C:\Windows\system32\ja-JP
            2009-01-18 01:07:31 ----D---- C:\Windows\system32\wbem
            2009-01-18 01:07:31 ----D---- C:\Windows\system32\tr-TR
            2009-01-18 01:07:29 ----D---- C:\Windows\system32\nl-NL
            2009-01-18 01:07:29 ----D---- C:\Windows\system32\nb-NO
            2009-01-18 01:07:29 ----D---- C:\Windows\system32\ar-SA
            2009-01-18 01:07:27 ----D---- C:\Windows\system32\migwiz
            2009-01-18 01:07:26 ----D---- C:\Windows\system32\pt-BR
            2009-01-18 01:06:14 ----D---- C:\Windows\AppPatch
            2009-01-18 01:03:48 ----D---- C:\Windows\Boot
            2009-01-18 01:03:44 ----D---- C:\Windows\system32\Boot
            2009-01-18 00:46:59 ----A---- C:\Windows\system32\ifxcardm.dll
            2009-01-18 00:46:57 ----A---- C:\Windows\system32\axaltocm.dll
            2009-01-10 02:35:28 ----A---- C:\Windows\system32\mrt.exe
            2009-01-01 22:48:51 ----D---- C:\ProgramData\Adobe
            2008-12-23 10:05:53 ----SD---- C:\Users\Utilisateur\AppData\Roaming\Microsoft
            2008-12-18 23:25:58 ----SD---- C:\ProgramData\Microsoft
            2008-12-18 08:44:32 ----D---- C:\Program Files\Common Files\microsoft shared
            2008-12-17 22:14:33 ----D---- C:\Windows\LiveKernelReports
            2008-12-13 20:08:00 ----D---- C:\Users\Utilisateur\AppData\Roaming\LimeWire
            2008-12-12 03:02:15 ----D---- C:\ProgramData\Microsoft Help

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2007-02-27 11840]
            R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
            R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
            R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
            R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248]
            R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
            R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
            R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
            R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
            R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 8704]
            R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-04-18 141312]
            R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2007-08-28 146560]
            R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2008-05-20 52032]
            R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
            R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-03-04 188416]
            R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
            R3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
            R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
            R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
            R3 NETw4v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-28 2222080]
            R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-19 7626400]
            R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
            R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-19 88576]
            R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
            R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
            R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
            R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-20 278528]
            S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
            S3 catchme;catchme; \??\C:\Users\UTILIS~1\AppData\Local\Temp\catchme.sys []
            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
            S3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
            S3 EU3_USB;WLAN miniUSB Adapter Driver; C:\Windows\system32\DRIVERS\EU3USB.sys [2004-02-13 690176]
            S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-10-01 183352]
            S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
            S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
            S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2009-01-14 38496]
            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
            S3 NETw3v32;Pilote de carte Intel(R) PRO/Wireless 3945ABG pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
            S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
            S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
            S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\Windows\system32\DRIVERS\SymIM.sys []
            S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
            S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
            S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
            S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
            S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
            S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 AntiVirScheduler;Planificateur Avira AntiVir Personal - Free Antivirus; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
            R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
            R2 DpHost;Biometric Authentication Service; C:\Program Files\DigitalPersona\Bin\DpHostW.exe [2007-09-20 299008]
            R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-09-25 65536]
            R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
            R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
            R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
            R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-09-30 271760]
            R2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-09-30 112016]
            R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
            R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-07-10 386560]
            S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
            S3 GameConsoleService;GameConsoleService; C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2008-05-05 165416]
            S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
            S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
            S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

            -----------------EOF-----------------
            0
          3. heu...
            je ne trouve pas le doc "info txt"
            lorsque je vais dans c: je ne trouve que celui du 2/2/09
            alors que le doc "log.txt du 9 s'y trouve bien
            c est d'ailleurs le seul que je vois dans la barre de tache !?!

            pas doué, moi :/
            0
        7. Salut genhackman,je te laisse mener la manoeuvre
          0
          1. Salut a tous j'ai laissé tomber Windows_7 car trop de bugs a force d'utilisation

            ils disent quie c est une vversion stable et ben pas un brin

            (tu me diras je l ai teste sur un vieux P4 qui a la pompe a eau en panne lol)
            0
            1. lut ! genhackman :)
              de toutes les facons, on l utilisera tous, comme d'hab...
              lol
              0
          2. Bon il fait quoi le marseillais,il est entrain de boire son café?Comment va l'ordinateur sinon?Moins pire qu'avant quand meme
            0
            1. ben l a pas bougé depuis la derniere fois
              lol
              pas touché, Val
              lol
              0
            2. mais vais te dire ca,
              je viens de lancer un scann avec antivir
              0
          3. Ben oui ca va moi,ca ferait juste plaisir de retrouver la cheleur,meme dans le sud ,il fait pas tres beau.
            0
            1. je crois qu on a tous besoin de soleil, en ce moment !
              0
          4. Bon y'a genhackmen aussi
            0
            1. bonjour, genhackmen !
              marche le nouveau windows ?
              0
          5. Salut Val,

            Moi je suis là.
            0
            1. bonjour, Lolo c est Phil !
              Val a laissé tomber :)
              elle croit qu elle n y arrivera jamais avec son pc !
              découragée, elle !
              va, toi ?
              0
          6. ben e suis dessus actuelemnt et ca a l air de marcher plutot comme il faut sauf la transmission de fichiers (lol)
            0
            1. toc toc :)
              0
          7. looooooooooooooooooooooooooooooooooooooooooooooool
            0
            1. tu ne serais pas le 1er que windows énerve, Gen ! lol
              0
          8. windows 7i doit rendre bougon genhackman!!!!mdr
            0
            1. c est encourrageant
              lol
              0
            2. bonjour :)
              toujours la ?
              0
          9. Et pas de refaire la meme procedure de desinfection.C'est pour ca que je lui ai dit ,s'il le souhaite pour les autres ordinateurs de creer une nouvelle page et de reposter un rapport hijack this

            C'est windows qui te fait raler?
            0
            1. Je parlais de virer antivirus orange et de mettre antivir et pc tools firewall plus!!!!!J'espere qu'il a compris cela
              0
              1. c est bien ce que j avais compris ;)
                0
            • 1
            • 2
            • 3
            • 4
            • 5
            • 6
            • 7
            • 8
            • 9
            • 10