Aide pour virus

Bonjour, a tous .
Tout dabort g windos xp et g "pc tools spyware doctor", "antivir", "Malwarebytes' Anti-Malware", "JkDefragGUI" et " ccleaner".Voila, donc g netoyer et défragmenter mon ordi, mais c dans l'analyyse qu'il y a un hic.
Quand je fait une analyse de mon ordi avec spyware doctor c antivir qui me détècte des virus et spyware bugg (l'analyse ne progrèssse plus). antivir me dit qu'il a détècter un virus et me demande si que je veut en faire. Je lui dit de le suprimer mais quand je recomence une analyse il me retrouve le meme virus (Dans le fichier 'C:\Program Files\Spyware Doctor\avdb\temp\84DAF166.vbt'
un virus ou un programme indésirable 'TR/Unpacked.Gen' [trojan] a été détecté.)
Je voudrai savoir comment me débarasser de se virus ?, es ce que mes programmes sont de bonne qualiter ?
aider moi svp car mon ordi rame et bugg en plus de ça.
Merci d'avance a ce qui pourron m'aider et a ceux qui se pencheron sur mon sujet.
voila merci encore et j'attend avec impatience vos commentaire.
Salutation a tous.
Configuration: Windows XP Internet Explorer 7.0

30 réponses

Résumé de la discussion

Plusieurs utilisateurs rencontrent un problème de détection avec Spyware Doctor et un antivirus sur Windows XP, où le fichier C:\Program Files\Spyware Doctor\avdb\temp\84DAF166.vbt signale le Trojan TR/Unpacked.Gen. Des essais complémentaires d'outils comme Ad-Remover et Malwarebytes apparaissent dans le fil pour nettoyer les éléments détectés et les adwares, mais des rapports indiquent des conflits entre outils et des détections non résolues. En cause, des éléments publicitaires potentiels (Everest Poker, EoRezo, ItsLabel, SweetIM) et des programmes indésirables répertoriés qui nécessitent des nettoyages manuels et une vérification du système. D'autres échanges suggèrent que la surmultiplication des sécurité peut provoquer des conflits et qu'il convient de limiter les outils actifs et de vérifier les retours des rapports antivirus.

Bobot (l’IA à votre service)
  1. je te remercie beaucoup pour ton aide l'ami , mais la je v me coucher , je suis mort de fatigue . Es ce qu'on peut remetre ca a plus tard et puis-je te recontacter par la suite ?
    0
    1. Re,

      ▶ Télécharge et installe MalwareByte's Anti-Malware
      Malwarebyte

      ▶ Mets le à jour

      ▶ Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.

      ▶ Sélectionne Exécuter un examen COMPLET si ce n'est pas déjà fait

      ▶ clique sur Rechercher

      ▶ Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

      ▶ Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

      ▶ Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

      ▶ Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

      Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

      Tutoriel pour MalwareByte's

      Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
      0
      1. et voici le 2nd
        info.txt logfile of random's system information tool 1.06 2009-05-17 02:40:01

        ======Uninstall list======

        -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        7-Zip 4.42-->"C:\Program Files\7-Zip\Uninstall.exe"
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
        Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
        Ad-remover-->C:\Program Files\Ad-remover\Uninstall ADR.exe
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
        Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
        Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
        EasyRecovery Professional-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{268723B7-A994-4286-9F85-B974D5CAFC7B} /l1036
        Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
        GalleryPlayer Images-->C:\WINDOWS\GalleryPlayer Images Uninstaller.exe
        GameShadow-->MsiExec.exe /I{5A2F371F-8B5D-46B4-833C-0612B065BEC7}
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
        Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
        Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Document Viewer 7.0-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
        HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Photosmart, Officejet and Deskjet 7.0.A-->C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
        HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
        HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        JkDefragGUI 1.03-->C:\Program Files\JkDefragGUI\Uninstall.exe
        K-Lite Mega Codec Pack 1.57-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        LimeWire 5.1.1-->"C:\Program Files\LimeWire\uninstall.exe"
        Ma-Config.com-->MsiExec.exe /X{05B3F57E-036B-4999-BAE4-E60E82F75442}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
        MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
        Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
        Neuf Giga Drive v2.8.0-->"C:\Program Files\Neufgiga drive\Neuf Giga Drive\unins000.exe"
        Norton Security Scan (Symantec Corporation)-->"C:\Program Files\Fichiers communs\Symantec Shared\NSSSetup\{1E86581C-2858-4094-AB8B-D005EF96D4AC}_2_0_0\NSSSetup.exe" /X
        Norton Security Scan-->MsiExec.exe /X{1E86581C-2858-4094-AB8B-D005EF96D4AC}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
        OCR Software by I.R.I.S 7.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}
        Online Armor 1.1-->"C:\Program Files\Tall Emu\Online Armor\unins000.exe"
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
        PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x40c -removeonly
        skin DOLCE & GABBAN-->C:\Program Files\MSN Messenger\Uninstal.exe
        Spyware Doctor 6.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
        Stronghold Legends-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{66A405D2-BA14-4594-BF36-B3B544F0754E}\setup.exe" -l0x40c -removeonly
        Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
        Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
        Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
        Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
        Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
        Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        XnView 1.82.2-->"C:\Program Files\XnView\unins000.exe"
        XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe"

        ======Security center information======

        AV: Avira AntiVir PersonalEdition Classic
        AV: Online Armor AV+ (disabled)

        ======System event log======

        Computer Name: PARET
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{333188B4-D27E-4E50-AC89-864B48C6E7A3} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 49527
        Source Name: Tcpip
        Time Written: 20090510140016.000000+120
        Event Type: Informations
        User:

        Computer Name: PARET
        Event Code: 2
        Message: Device identified.

        Record Number: 49526
        Source Name: nvata
        Time Written: 20090510140016.000000+120
        Event Type: Informations
        User:

        Computer Name: PARET
        Event Code: 2
        Message: Device identified.

        Record Number: 49525
        Source Name: nvata
        Time Written: 20090510140016.000000+120
        Event Type: Informations
        User:

        Computer Name: PARET
        Event Code: 6005
        Message: Le service d'Enregistrement d'événement a démarré.

        Record Number: 49524
        Source Name: EventLog
        Time Written: 20090510140009.000000+120
        Event Type: Informations
        User:

        Computer Name: PARET
        Event Code: 6009
        Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

        Record Number: 49523
        Source Name: EventLog
        Time Written: 20090510140009.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: PARRET
        Event Code: 12001
        Message: The Messenger Sharing USN Journal Reader service started successfully.

        Record Number: 3126
        Source Name: usnjsvc
        Time Written: 20080612182710.000000+120
        Event Type:
        User:

        Computer Name: PARRET
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 3125
        Source Name: SecurityCenter
        Time Written: 20080612182404.000000+120
        Event Type: Informations
        User:

        Computer Name: PARRET
        Event Code: 0
        Message:
        Record Number: 3124
        Source Name: gusvc
        Time Written: 20080612182356.000000+120
        Event Type: Informations
        User:

        Computer Name: PARRET
        Event Code: 1517
        Message: Windows a sauvegardé le Registre utilisateur PARRET\Fabien alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

        Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

        Record Number: 3123
        Source Name: Userenv
        Time Written: 20080611222632.000000+120
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PARRET
        Event Code: 101
        Message: msnmsgr (3412) Le moteur de base de données est arrêté.

        Record Number: 3122
        Source Name: ESENT
        Time Written: 20080611210130.000000+120
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 44 Stepping 0, AuthenticAMD
        "PROCESSOR_REVISION"=2c00
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP

        -----------------EOF-----------------
        0
        1. re re, voila pour le 1er raport
          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Fabien at 2009-05-17 02:39:45
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 6 GB (27%) free of 20 GB
          Total RAM: 1023 MB (57% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 02:39:55, on 17/05/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16827)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\WgaTray.exe
          C:\WINDOWS\system32\RunDLL32.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Documents and Settings\Fabien\Local Settings\Temporary Internet Files\Content.IE5\K28P6UFW\RSIT[1].exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Program Files\Trend Micro\HijackThis\Fabien.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = titoubew
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
          O4 - HKLM\..\RunOnce: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe" /fork
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/...
          O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
          O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
          O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
          0
          1. re , ca y est g Désinstalle findykill.

            mais que doit-je relancer?
            0
            1. Re,

              ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

              ▶ Double clique sur RSIT.exe pour lancer l'outil.

              ▶ Clique sur ' continue ' à l'écran Disclaimer.

              ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

              ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
              ( log.txt & info.txt )

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
              0
              1. Re,

                Désinstalle findykill.

                relance rsit.
                0
                1. re re , voila

                  ############################## [ FindyKill V4.728 ]

                  # User : Fabien (Administrateurs) # PARET
                  # Update on 13/05/09 by Chiquitine29
                  # Start at: 02:21:20 | 17/05/2009
                  # Website : http://pagesperso-orange.fr/NosTools/findykill.html

                  # AMD Sempron(tm) Processor 3000+
                  # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                  # Internet Explorer 7.0.5730.11
                  # Windows Firewall Status : Enabled
                  # AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
                  # AV : Online Armor AV+ 65537 [ (!) Disabled | Updated ]

                  # C:\ # Disque fixe local # 19,99 Go (5,41 Go free) # NTFS
                  # D:\ # Disque fixe local # 132,66 Go (101,64 Go free) # NTFS
                  # E:\ # Disque CD-ROM
                  # F:\ # Disque amovible # 496,25 Mo (61,29 Mo free) [FAB] # FAT32

                  ############################## [ Active Processes ]

                  ################## [ Infected Files \ Folders ]

                  Deleted ! C:\WINDOWS\Prefetch\PATCH.EXE-044E27E2.pf

                  ################## [ Infected Temp Files ]

                  ################## [ Registry / Infected keys ]

                  ################## [ Cleaning Removable drives ]

                  Deleted ! D:\autorun.inf

                  ################## [ Registry / Mountpoint2 ]

                  # -> Not found !

                  ################## [ States / Restarting of services ]

                  # Services : [ Auto=2 / Request=3 / Disable=4 ]

                  # Ndisuio -> # Type of startup =3
                  # Ip6Fw -> # Type of startup =2
                  # SharedAccess -> # Type of startup =2
                  # wuauserv -> # Type of startup =2
                  # wscsvc -> # Type of startup =2

                  ################## [ Searching Other Infections ]

                  # -> Nothing found.

                  ################################### [ Cracks / Keygens / Serials ]

                  # -> Nothing found !

                  ################## [ ! End of Report # FindyKill V4.728 ! ]
                  0
                  1. Re,

                    Findykill de chiquitine29 option 2:

                    ▶ Branche tes disques amovibles à ton PC ( (clefs USB, disque dur externe, etc...) sans les ouvrir

                    ▶ Double-clique sur le raccourci FindyKill sur ton bureau

                    ▶ Au menu principal, choisisl'option 2 (Suppression)

                    /!\ Il y aura 1 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

                    ▶ Ensuite, poste le rapport FindyKill.txt

                    Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

                    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                    0
                    1. re,
                      voila le raport docteur , quel est le bilan?

                      ############################## [ FindyKill V4.728 ]

                      # User : Fabien (Administrateurs) # PARET
                      # Update on 13/05/09 by Chiquitine29
                      # Start at: 02:11:05 | 17/05/2009
                      # Website : http://pagesperso-orange.fr/NosTools/findykill.html

                      # AMD Sempron(tm) Processor 3000+
                      # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                      # Internet Explorer 7.0.5730.11
                      # Windows Firewall Status : Enabled
                      # AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
                      # AV : Online Armor AV+ 65537 [ (!) Disabled | Updated ]

                      # C:\ # Disque fixe local # 19,99 Go (5,41 Go free) # NTFS
                      # D:\ # Disque fixe local # 132,66 Go (101,64 Go free) # NTFS
                      # E:\ # Disque CD-ROM

                      ############################## [ Processus actifs ]

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Spyware Doctor\pctsTray.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\Program Files\Spyware Doctor\pctsAuxs.exe
                      C:\Program Files\Spyware Doctor\pctsSvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\WgaTray.exe
                      C:\WINDOWS\explorer.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe

                      ################## [ Fichiers / Dossiers infectieux ]

                      Found ! C:\WINDOWS\Prefetch\PATCH.EXE-044E27E2.pf

                      ################## [ Infected Temp Files ]

                      ################## [ Registre / Clés infectieuses ]

                      ################## [ Recherche dans supports amovibles]

                      Found ! D:\autorun.inf

                      ################## [ Registre / Mountpoints2 ]

                      # -> Not found !

                      ################## [ ! Fin du rapport # FindyKill V4.728 ! ]
                      0
                      1. Re,

                        Télécharge FindyKill de Chiquitine29

                        ▶ Fais un clique droit sur le lien et choisis ( "enregistrer la cible sous ...." )( , destination le bureau .

                        ▶ Laisse toi guider pour l'installer.

                        ▶ Double clic sur " FindyKill." pour lancer l'outil .

                        ▶ Choisis La langue:F pour français

                        ▶ Choisis l'option 1 . Puis laisses travailler ...

                        ▶ Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

                        ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

                        Les-risques-securitaires-du-peer-to-peer

                        Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                        0
                        1. ca marche pas il me dit que ce n'est pas une application win32 valide
                          0
                          1. pourquoi dois-je faire tout ca g un virus ?! les raport signale une anomalie
                            0
                            1. Re,

                              ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

                              ▶ Double clique sur RSIT.exe pour lancer l'outil.

                              ▶ Clique sur ' continue ' à l'écran Disclaimer.

                              ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                              ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
                              ( log.txt & info.txt )

                              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                              Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                              0
                              1. re, voila le raport

                                ------- LOGFILE OF AD-REMOVER 1.1.3.9 | ONLY XP/VISTA -------

                                Updated by C_XX on 16/05/2009 at 21:15
                                Contact: AdRemover.contact@gmail.com
                                Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

                                **** LIMITED TO ****

                                Known Adwares
                                Eorezo
                                It's TV

                                ********************

                                Start at: 1:14:55, 17/05/2009 | Boot mode: Normal Boot
                                Option: Clean | Executed from: C:\Program Files\Ad-remover\
                                Operating System: Microsoft® Windows XP™ Service Pack 2 V5.1.2600
                                Computer Name: PARET
                                Current User: Fabien - Administrator
                                Drive(s):
                                - C:\ (File System: NTFS)
                                - D:\ (File System: NTFS)

                                (!) -- IE start pages/Tabs reset

                                ============ Known Adwares Deleted ============

                                .
                                HKCU\Software\Grand Virtual
                                HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
                                .
                                C:\Documents and Settings\All Users\Menudm~1\Progra~1\Everest Poker
                                C:\Program Files\Everest Poker
                                C:\Documents and Settings\Fabien\Cookies\fabien@atdmt[1].txt

                                +-----------------| Eorezo Elements Deleted :

                                HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                                HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                                HKCU\Software\EoRezo
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                                HKLM\Software\EoRezo
                                .
                                C:\Program Files\EoRezo
                                C:\Documents and Settings\Fabien\Application Data\EoRezo

                                +-----------------| It's TV Elements Deleted :

                                HKCU\Software\ItsLabel
                                HKLM\Software\ItsLabel
                                .
                                C:\Documents and Settings\Fabien\Application Data\ItsLabel

                                (!) -- Temp files deleted.
                                (!) -- Recycle bin emptied in all drives.

                                +-----------------| Added Scan:

                                ---- Mozilla FireFox Version [Unable to get version] ----

                                ProfilePath: hy762xfj.default (Fabien)
                                .
                                (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
                                (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
                                (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
                                (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.1");
                                (Prefs.js) user_pref("google.toolbar.subscribe.aggregators.iGoogle.url", "hxxp://fusion.google.com/add?feeduhú†rl=%húWfeedhúW%&clhúWien(user_pref("browser.startup.homepage", "hxxp://lo.st");
                                .

                                ---- Internet Explorer Version 7.0.5730.11 ----

                                [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                Search Page: hxxp://www.google.com
                                Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                                [HKEY_USERS\S-1-5-21-329068152-1844237615-839522115-1003\..\Internet Explorer\Main]

                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                Search Page: hxxp://www.google.com
                                Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                                [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Search bar: hxxp://search.msn.com/spbasic.htm
                                Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Start Page: hxxp://fr.msn.com/

                                [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                                Tabs: hxxp://ieframe.dll/tabswelcome.htm

                                =========== Suspicious ==========

                                C:\Documents and Settings\Fabien\Mes documents\Stronghold Legends\patch.exe
                                [73875949 Byte(s)|--a------|01/05/2009 22:13|HashMD5: fca97c0142a6edc26a01dca8bd832f91 |CRC32: 6ba18470]

                                +---------------------------------------------------------------------------+

                                3904 Byte(s) - C:\Ad-Report-Clean-17.05.2009.log
                                3823 Byte(s) - C:\Ad-Report-Scan-17.05.2009.log

                                19 File(s) - C:\Program Files\Ad-remover\BACKUP
                                1 File(s) - C:\Program Files\Ad-remover\QUARANTINE

                                End at: 1:39:10 | 17/05/2009
                                .
                                +-----------------| E.O.F
                                .
                                0
                                1. Re,

                                  !Déconnectes toi et fermes toutes applications en cours !

                                  ● Relances "Ad-remover" : au menu principal choisi l'option "B" .

                                  ● Coche à l'écran de sélèction ( http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG ) :

                                  1 - Suppression Adwares connus
                                  2 - Suppression Eorezo
                                  3 - Suppression It's TV

                                  ● Puis choisi "S" , le programme va travailler,

                                  ● Postes le rapport qui apparait à la fin.

                                  ( le rapport est sauvegardé sous C:\Ad-report(date).log )

                                  (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  /!\Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides)
                                  0
                                  1. merci voila le rapport ad remover

                                    ------- LOGFILE OF AD-REMOVER 1.1.3.9 | ONLY XP/VISTA -------

                                    Updated by C_XX on 16/05/2009 at 21:15
                                    Contact: AdRemover.contact@gmail.com
                                    Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

                                    Start at: 0:22:03, 17/05/2009 | Boot mode: Normal Boot
                                    Option: Scan | Executed from: C:\Program Files\Ad-remover\
                                    Operating System: Microsoft® Windows XP™ Service Pack 2 V5.1.2600
                                    Computer Name: PARET
                                    Current User: Fabien - Administrator
                                    Drive(s):
                                    - C:\ (File System: NTFS)
                                    - D:\ (File System: NTFS)

                                    ============ Known Adwares Found ============

                                    .
                                    HKCU\Software\Grand Virtual
                                    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
                                    .
                                    C:\Documents and Settings\All Users\Menudm~1\Progra~1\Everest Poker
                                    C:\Program Files\Everest Poker
                                    C:\Documents and Settings\Fabien\Cookies\fabien@atdmt[1].txt

                                    +-----------------| Eorezo Elements Found:

                                    HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                                    HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                                    HKCU\Software\EoRezo
                                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                                    HKLM\Software\EoRezo
                                    HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                                    HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                                    HKU\S-1-5-21-329068152-1844237615-839522115-1003\Software\Eorezo
                                    .
                                    C:\Program Files\EoRezo
                                    C:\Documents and Settings\Fabien\Application Data\EoRezo

                                    +-----------------| It's TV Elements Found:

                                    HKCU\Software\ItsLabel
                                    HKLM\Software\ItsLabel
                                    HKU\S-1-5-21-329068152-1844237615-839522115-1003\Software\ItsLabel
                                    .
                                    C:\Documents and Settings\Fabien\Application Data\ItsLabel

                                    +-----------------| Sweetim Elements Found:

                                    .

                                    +-----------------| Added Scan:

                                    ---- Mozilla FireFox Version [Unable to get version] ----

                                    ProfilePath: hy762xfj.default (Fabien)
                                    .
                                    (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
                                    (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
                                    (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
                                    (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.1");
                                    (Prefs.js) user_pref("google.toolbar.subscribe.aggregators.iGoogle.url", "hxxp://fusion.google.com/add?feeduhú†rl=%húWfeedhúW%&clhúWien(user_pref("browser.startup.homepage", "hxxp://lo.st");
                                    .

                                    ---- Internet Explorer Version 7.0.5730.11 ----

                                    [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                                    Search bar: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                    Search Page: hxxp://www.google.com
                                    Start Page: hxxp://www.neufportail.fr/

                                    [HKEY_USERS\S-1-5-21-329068152-1844237615-839522115-1003\..\Internet Explorer\Main]

                                    Search bar: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                    Search Page: hxxp://www.google.com
                                    Start Page: hxxp://www.neufportail.fr/

                                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                                    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                                    Default_Search_URL: hxxp://recherche.neuf.fr/
                                    Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                    Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

                                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                                    Tabs: hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9

                                    =========== Suspicious ==========

                                    C:\Documents and Settings\Fabien\Mes documents\Stronghold Legends\patch.exe
                                    [73875949 Byte(s)|--a------|01/05/2009 22:13|HashMD5: fca97c0142a6edc26a01dca8bd832f91 |CRC32: 6ba18470]

                                    +---------------------------------------------------------------------------+

                                    3606 Byte(s) - C:\Ad-Report-Scan-17.05.2009.log

                                    0 File(s) - C:\Program Files\Ad-remover\BACKUP
                                    0 File(s) - C:\Program Files\Ad-remover\QUARANTINE

                                    End at: 0:43:46 | 17/05/2009
                                    .
                                    +-----------------| E.O.F
                                    .
                                    1
                                    1. Oui Boonty provient de jeu téléchargé sur yahoo d'après quelques recherche que j'ai faite

                                      Mais j suis pas encore a votre niveau donc je ne dit rien et j apprend encore !
                                      0
                                      • 1
                                      • 2