Pb redirection gomeo bing

Résolu
Bonjour, g un pb de redirection sur des sites tels que gomeo bing ou autres...g recherché des solutions possible et je me suis rendu compte qu'il existé un moyen comme zhpdiag ki serai susceptible de m'arranger ca...seulement il faut l'aide d'un pro apparemment g bien vu sur tt les forums les échanges de manips! g donc deja le fameux lien : http://www.cijoint.fr/cjlink.php?file=cj201010/cij7u7vFIG.txt je cherche un courageux qui me filerai un coup de main pour désinfecter mon pc! merci d'avance a plusss!

je suis sous xp sp3 version maddog

26 réponses

  1. Contributeur sécurité
    Telecharge combofix :
    Faire un clic droit sur le lien
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    * Choisir : "Enregistrer la cible du lien sous..."
    * Choisir le Bureau comme destination.
    * Dans le champ "Nom du fichier", renommer ComboFix.exe en CCM.exe par exemple, puis enregistrer.
    * Attention ! L'étape de renommage est obligatoire sous peine de voir afficher le message "ComboFix.exe n'est pas une application win32 valide" et de le rendre ainsi totalement inefficace.

    Note importante :tu est sous Vista

    la désactivation du Contrôle des comptes utilisateurs est obligatoire

    Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac­er-l-uac

    pour toute manipulation fait comme ceci( clic droit "exécuter en tant qu'administrateur" pour Vista/7 )

    -> Double clique combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    -Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. risque de figer l'ordi

    - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    !\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordi (plantage complet)

    ::Si combofix detecte quelque chose et de demande a redémarrer tu accepte
    2
    1. j'ai problème avec goméo; j'ai déjà fait les démarches avec combofix voilà le rapport:

      ComboFix 10-11-11.01 - GRISONI 11/11/2010 21:37:00.1.2 - x86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1275 [GMT 1:00]
      Lancé depuis: c:\documents and settings\GRISONI\Bureau\ComboFix.exe
      AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
      AV: Lavasoft Ad-Watch Live! Antivirus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\GRISONI\Application Data\Mozilla\Firefox\Profiles\77gc067l.default\extensions\{6b8a37a3-9913-4387-8714-571dc244232b}
      c:\documents and settings\GRISONI\Application Data\Mozilla\Firefox\Profiles\77gc067l.default\extensions\{6b8a37a3-9913-4387-8714-571dc244232b}\chrome.manifest
      c:\documents and settings\GRISONI\Application Data\Mozilla\Firefox\Profiles\77gc067l.default\extensions\{6b8a37a3-9913-4387-8714-571dc244232b}\chrome\xulcache.jar
      c:\documents and settings\GRISONI\Application Data\Mozilla\Firefox\Profiles\77gc067l.default\extensions\{6b8a37a3-9913-4387-8714-571dc244232b}\defaults\preferences\xulcache.js
      c:\documents and settings\GRISONI\Application Data\Mozilla\Firefox\Profiles\77gc067l.default\extensions\{6b8a37a3-9913-4387-8714-571dc244232b}\install.rdf
      c:\windows\Downloaded Program Files\popcaploader.dll
      c:\windows\Downloaded Program Files\popcaploader.inf
      c:\windows\patch.exe
      c:\windows\system32\1043561293
      c:\windows\system32\1043561293\4.rar
      c:\windows\system32\spool\prtprocs\w32x86\CNMPP49.DLL
      c:\windows\system32\spool\prtprocs\w32x86\CNMPP76.DLL

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2010-10-11 au 2010-11-11 ))))))))))))))))))))))))))))))))))))
      .

      2010-11-11 19:29 . 2010-09-23 07:46 15880 ----a-w- c:\windows\system32\lsdelete.exe
      2010-11-11 17:13 . 2010-09-23 07:46 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
      2010-11-11 17:06 . 2010-11-11 17:06 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}
      2010-11-01 13:49 . 2010-11-01 15:09 -------- d-----w- c:\documents and settings\GRISONI\Application Data\skypePM
      2010-10-27 18:51 . 2010-10-27 18:51 -------- d-----w- c:\program files\Fichiers communs\Skype
      2010-10-27 18:50 . 2010-11-01 21:26 -------- d-----w- c:\documents and settings\GRISONI\Application Data\Skype
      2010-10-27 18:50 . 2010-10-27 18:51 -------- d-----r- c:\program files\Skype
      2010-10-27 18:50 . 2010-10-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
      2010-10-27 18:48 . 2010-10-27 18:48 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
      2010-10-19 18:07 . 2010-10-19 18:07 -------- d-----w- c:\program files\VS Revo Group
      2010-10-13 13:47 . 2010-09-18 06:53 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
      2010-10-13 13:47 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
      2010-10-13 13:47 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-11-11 19:29 . 2010-08-30 08:40 556 ---ha-w- C:\aaw7boot.cmd
      2010-11-11 17:13 . 2009-11-08 10:38 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
      2010-09-18 10:23 . 2005-09-01 05:53 974848 ----a-w- c:\windows\system32\mfc42u.dll
      2010-09-18 06:53 . 2005-09-01 05:53 974848 ----a-w- c:\windows\system32\mfc42.dll
      2010-09-18 06:53 . 2005-09-01 05:53 954368 ------w- c:\windows\system32\mfc40.dll
      2010-09-18 06:53 . 2005-09-01 05:53 953856 ----a-w- c:\windows\system32\mfc40u.dll
      2010-09-09 13:34 . 2005-09-01 05:53 832512 ----a-w- c:\windows\system32\wininet.dll
      2010-09-09 13:34 . 2005-09-01 05:53 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
      2010-09-09 13:34 . 2005-09-01 05:53 78336 ----a-w- c:\windows\system32\ieencode.dll
      2010-09-09 13:34 . 2005-09-01 05:53 17408 ----a-w- c:\windows\system32\corpol.dll
      2010-09-08 15:57 . 2005-09-01 05:53 389120 ----a-w- c:\windows\system32\html.iec
      2010-09-07 15:12 . 2010-08-31 09:28 38848 ----a-w- c:\windows\avastSS.scr
      2010-09-07 15:11 . 2010-08-31 09:28 167592 ----a-w- c:\windows\system32\aswBoot.exe
      2010-09-07 14:52 . 2010-08-31 09:28 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
      2010-09-07 14:52 . 2010-08-31 09:28 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
      2010-09-07 14:47 . 2010-08-31 09:28 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
      2010-09-07 14:47 . 2010-08-31 09:28 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
      2010-09-07 14:47 . 2010-08-31 09:28 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
      2010-09-07 14:47 . 2010-08-31 09:28 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
      2010-09-07 14:46 . 2010-08-31 09:28 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
      2010-09-01 11:51 . 2005-09-01 05:52 285824 ----a-w- c:\windows\system32\atmfd.dll
      2010-09-01 07:55 . 2007-04-11 20:32 1852928 ----a-w- c:\windows\system32\win32k.sys
      2010-08-29 08:23 . 2010-08-29 08:23 203776 --sh--w- c:\windows\system32\unrar.exe
      2010-08-27 08:02 . 2005-09-01 05:53 119808 ----a-w- c:\windows\system32\t2embed.dll
      2010-08-27 05:58 . 2005-09-01 05:53 99840 ----a-w- c:\windows\system32\srvsvc.dll
      2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
      2010-08-26 13:39 . 2006-03-24 23:27 357248 ----a-w- c:\windows\system32\drivers\srv.sys
      2010-08-23 16:12 . 2005-09-01 05:52 617472 ----a-w- c:\windows\system32\comctl32.dll
      2010-08-17 13:17 . 2005-09-01 05:53 58880 ----a-w- c:\windows\system32\spoolsv.exe
      2010-08-16 08:44 . 2005-09-01 05:53 590848 ----a-w- c:\windows\system32\rpcrt4.dll
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
      "mouseElf"="c:\progra~1\GENIUS~1\GNETMOUS.EXE" [2003-05-13 163840]
      "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]

      Que faut il faire ensuite????
      Merci
      0
      1. Contributeur sécurité
        Télécharge DelFix sur ton bureau.

        http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

        3.1 - Option Recherche

        Téléchargez DelFix sur votre bureau.
        Lancez le, tapez 1 et validez en appuyant sur [Entrée]
        Patientez quelques secondes puis copiez/collez le contenu du rapport qui s'ouvrira sur le forum qui vous prend en charge.

        Note : Le rapport est sauvegardé sous C:\DelFixSearch.txt

        -------------------------

        3.2 - Option Suppression

        Téléchargez DelFix sur votre bureau
        Lancez le, tapez 2 et validez en appuyant sur [Entrée]
        Patientez quelques secondes puis copiez/collez le contenu du rapport qui s'ouvrira sur le forum qui vous prend en charge.

        Note : Le rapport est sauvegardé sous C:\DelFixSuppr.txt
        0
        1. non un grand merci pour ta patience jte tiens au jus si ca marche pas^^ a+
          0
          1. Contributeur sécurité
            toujours gomeo ?
            0
            1. slt et dsl pour le retard j'avais pas vu la 2eme p)age^^ voila le rapport... : Rapport de ZHPFix 1.12.3206 par Nicolas Coolman, Update du 04/10/2010
              Rapport de ZHPFix 1.12.3206 par Nicolas Coolman, Update du 04/10/2010
              Fichier d'export Registre :
              Run by Administrateur at 17/10/2010 14:52:53
              Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
              Contact : nicolascoolman@yahoo.fr

              ========== Fichier(s) ==========
              c:\windows\system32\54a0cfb5 => Supprimé et mis en quarantaine

              ========== Récapitulatif ==========
              1 : Fichier(s)

              End of the scan
              0
              1. Contributeur sécurité
                Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

                O44 - LFC:[MD5.4ABBE352C16CAA3655E079F8AE4A3A0A] - 08/10/2010 - 19:20:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\54a0cfb5 [205]

                Puis Lance ZHPFix depuis le raccourci du bureau .

                * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

                * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitront .

                Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

                Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

                Copie/Colle le rapport à l'écran dans ton prochain message

                le rapport se trouve dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

                Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                Mais C.. de penser que ­tu es libre...Merci a australe13
                0
                1. http://www.cijoint.fr/cjlink.php?file=cj201010/cijnp707so.txt
                  0
                  1. Contributeur sécurité
                    Pour de plus amples informations, fait ceci stp

                    Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :

                    https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

                    Une fois le téléchargement achevé, dé zippe le fichier obtenu et place ZHPDiag.exe sur ton Bureau.

                    Double-clique sur l'icône pour lancer le programme. Sous Vista ou Seven clic droit « exécuter en tant que administrateur »

                    Clique sur la loupe pour lancer l'analyse.

                    Laisse l'outil travailler, il peut être assez long.

                    Ferme ZHPDiag en fin d'analyse.

                    Pour transmettre le rapport clique sur ce lien :

                    http://www.cijoint.fr/index.php
                    Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

                    Sélectionne le fichier ZHPDiag.txt.

                    Clique sur "Cliquez ici pour déposer le fichier".

                    Un lien de cette forme :

                    http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

                    est ajouté dans la page.

                    Copie ce lien dans ta réponse.
                    0
                    1. oui malheureusement au bout de 5 recherches par contre...ya de l'amelioration^^ par contre g vu ke les softs avaient deja virer pas mal de trucs...
                      0
                      1. Contributeur sécurité
                        Pb redirection gomeo toujours la ?
                        0
                        1. ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.9 ¤¤¤¤¤¤¤¤¤¤

                          User : Administrateur (Administrateurs)
                          Update on 09/10/2010 by g3n-h@ckm@n ::::: 15.30
                          Start at: 21:07:10 | 13/10/2010

                          Intel(R) Celeron(R) CPU 3.06GHz
                          Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 8.0.6001.18702
                          Windows Firewall Status : Disabled

                          C:\ -> Disque fixe local | NTFS
                          D:\ -> Disque CD-ROM
                          E:\ -> Disque amovible
                          F:\ -> Disque amovible
                          G:\ -> Disque amovible
                          H:\ -> Disque amovible
                          I:\ -> Disque amovible [BASS] | FAT32

                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                          Quarantined & Deleted !! : C:\Program Files\DAEMON Tools Toolbar

                          Quarantined & Deleted !! : C:\WINDOWS\System32\Autoruns.exe
                          Quarantined & Deleted !! : C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\SuggestedSites.dat

                          ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

                          127.0.0.1 localhost

                          ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

                          Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives

                          ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                          Local Page = C:\WINDOWS\system32\blank.htm
                          Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                          Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          Start Page = https://www.google.com/?gws_rd=ssl
                          Local Page = C:\WINDOWS\system32\blank.htm
                          Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                          ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                          AntiVirusDisableNotify = 0 (0x0)
                          AntiVirusOverride = 0 (0x0)
                          FirewallDisableNotify = 0 (0x0)
                          FirewallOverride = 0 (0x0)
                          UpdatesDisableNotify = 0 (0x0)
                          UpdatesOverride = 1 ()
                          FirstRunDisabled = 1 ()

                          ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

                          Ndisuio : Start = 3
                          EapHost : Start = 2
                          Ip6Fw : Start = 2
                          SharedAccess : Start = 2
                          wuauserv : Start = 2
                          wscsvc : Start = 2

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                          Disk Cleaned
                          anti-ver blaster : OK
                          Prefetch cleaned
                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                          FEATURE_BROWSER_EMULATION | svchost :
                          ====================================

                          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                          device: opened successfully
                          user: MBR read successfully
                          called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys SCSIPORT.SYS hal.dll SiSRaid.sys
                          kernel: MBR read successfully
                          user & kernel MBR OK

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                          0
                          1. Contributeur sécurité
                            Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                            mais cette fois-ci :

                            choisis l'option CLEAN

                            laisse travailler l'outil.

                            en fin de scan la fenêtre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau
                            0
                            1. comment ca moi aussi? de quelle domaine parles tu? g certes des aptitudes qui pourré bien aider...mais le temps beaucoup moins...j'imagine que tu doit dormir a cet heure ci voila du taf pour demain^^ le lien de cijoint.fr : http://www.cijoint.fr/cjlink.php?file=cj201010/cijNsORZTd.txt a dem!
                              0
                              1. Contributeur sécurité
                                merci pour ton aide de rien

                                tu est payé au moins pour ca?
                                non par plaisir et fierté on est tous bénévole toi aussi tu peut dans ton domaine

                                DÉSACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRÉSENTS !!!!!(car il est détecte a tort comme infection)

                                Télécharge ici :List_Kill'em de gen-hackman

                                http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe

                                et enregistre le sur ton bureau

                                windows 7 => clic droit "exécuter en tant que administrateur

                                sur le raccourci sur ton bureau pour lancer l'installation

                                Laisse coché :

                                Exécuter List_Kill'em

                                une fois terminée , clic sur "terminer" et le programme se lancera seul

                                Il commencera par telecharger et installer ses mises à jour , puis te donnera son menu

                                choisis l'option Search

                                laisse travailler l'outil

                                il se peut qu'une boite de dialogue s'ouvre , dans ce cas clique sur "ok" ou "Agrée"

                                à l'apparition de la fenetre blanche , c'est un peu long , c'est normal ,c'est une recherche supplementaire de fichiers cachés , le programme n'est pas bloqué.

                                Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                                ------ NE LE POSTE PAS SUR LE FORUM-------

                                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                                Clique sur Parcourir et cherche le fichier C:\List'em.txt

                                Clique sur Ouvrir.

                                Clique sur "Cliquez ici pour déposer le fichier".

                                Un lien de cette forme :

                                http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

                                est ajouté dans la page.

                                Copie ce lien dans ta réponse.
                                Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                                Mais C.. de penser que ­tu es libre...Merci a australe13
                                0
                                1. voila les deux rapports .. merci pour ton aide.. tu est payé au moins pour ca?!
                                  0
                                  1. Logfile of random's system information tool 1.08 (written by random/random)
                                    Run by Administrateur at 2010-10-12 23:39:52
                                    Microsoft Windows XP Professionnel Service Pack 3
                                    System drive C: has 94 GB (61%) free of 153 GB
                                    Total RAM: 1535 MB (60% free)

                                    Logfile of Trend Micro HijackThis v2.0.4
                                    Scan saved at 23:40:35, on 12/10/2010
                                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\AVG\AVG9\avgchsvx.exe
                                    C:\Program Files\AVG\AVG9\avgrsx.exe
                                    C:\Program Files\AVG\AVG9\avgcsrvx.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\Program Files\NTR global\NTRconnect\NTRconnect.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\Mozilla Firefox\plugin-container.exe
                                    C:\Documents and Settings\Administrateur\Mes documents\Téléchargements\RSIT.exe
                                    C:\Program Files\trend micro\Administrateur.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
                                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKUS\S-1-5-18\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User 'SYSTEM')
                                    O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User 'Default user')
                                    O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                                    O8 - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
                                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
                                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
                                    O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
                                    O9 - Extra 'Tools' menuitem: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{4743A6D2-D418-4F2C-8C75-DF6FD5B2F340}: NameServer = 80.10.246.2,80.10.246.129
                                    O17 - HKLM\System\CS1\Services\Tcpip\..\{4743A6D2-D418-4F2C-8C75-DF6FD5B2F340}: NameServer = 80.10.246.2,80.10.246.129
                                    O17 - HKLM\System\CS2\Services\Tcpip\..\{4743A6D2-D418-4F2C-8C75-DF6FD5B2F340}: NameServer = 80.10.246.2,80.10.246.129
                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                                    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
                                    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
                                    O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                    O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                    O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
                                    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                                    O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                    O23 - Service: NTRConnect (ntrconnect) - Unknown owner - C:\Program Files\NTR global\NTRconnect\NTRconnect.exe
                                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                                    O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
                                    0
                                    1. info.txt logfile of random's system information tool 1.08 2010-10-12 23:40:39

                                      ======Uninstall list======

                                      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -maintain activex
                                      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
                                      Ad-Remover By C_XX-->C:\Program Files\Ad-Remover\Uninstall.exe
                                      Apple Application Support-->MsiExec.exe /I{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}
                                      Apple Mobile Device Support-->MsiExec.exe /I{85991ED2-010C-4930-96FA-52F43C2CE98A}
                                      Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}
                                      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                                      AVG 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
                                      Bonjour-->MsiExec.exe /X{0CB9668D-F979-4F31-B8B8-67FE90F929F8}
                                      CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
                                      Dongle Sagem 760A-->C:\PROGRA~1\FICHIE~1\France Telecom\LIVEBOX_SAGEM_760A\0\uninstHardComponent.exe Uninstall.ini
                                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                                      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                                      iTunes-->MsiExec.exe /I{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}
                                      Java(TM) 6 Update 21-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216018FF}
                                      LimeWire 5.5.16-->"C:\Program Files\LimeWire\uninstall.exe"
                                      Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                      Media Player Classic - Home Cinema v. 1.3.1249.0-->"C:\Program Files\MPC HomeCinema\unins000.exe"
                                      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                                      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                      Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                                      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                                      Microsoft Office Access MUI (French) 2010-->MsiExec.exe /X{90140000-0015-040C-0000-0000000FF1CE}
                                      Microsoft Office Excel MUI (French) 2010-->MsiExec.exe /X{90140000-0016-040C-0000-0000000FF1CE}
                                      Microsoft Office Groove MUI (French) 2010-->MsiExec.exe /X{90140000-00BA-040C-0000-0000000FF1CE}
                                      Microsoft Office InfoPath MUI (French) 2010-->MsiExec.exe /X{90140000-0044-040C-0000-0000000FF1CE}
                                      Microsoft Office OneNote MUI (French) 2010-->MsiExec.exe /X{90140000-00A1-040C-0000-0000000FF1CE}
                                      Microsoft Office Outlook MUI (French) 2010-->MsiExec.exe /X{90140000-001A-040C-0000-0000000FF1CE}
                                      Microsoft Office PowerPoint MUI (French) 2010-->MsiExec.exe /X{90140000-0018-040C-0000-0000000FF1CE}
                                      Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}
                                      Microsoft Office Professionnel Plus 2010-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS
                                      Microsoft Office Proof (Arabic) 2010-->MsiExec.exe /X{90140000-001F-0401-0000-0000000FF1CE}
                                      Microsoft Office Proof (Dutch) 2010-->MsiExec.exe /X{90140000-001F-0413-0000-0000000FF1CE}
                                      Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
                                      Microsoft Office Proof (French) 2010-->MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}
                                      Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
                                      Microsoft Office Proof (Spanish) 2010-->MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}
                                      Microsoft Office Proofing (French) 2010-->MsiExec.exe /X{90140000-002C-040C-0000-0000000FF1CE}
                                      Microsoft Office Publisher MUI (French) 2010-->MsiExec.exe /X{90140000-0019-040C-0000-0000000FF1CE}
                                      Microsoft Office Shared MUI (French) 2010-->MsiExec.exe /X{90140000-006E-040C-0000-0000000FF1CE}
                                      Microsoft Office Word MUI (French) 2010-->MsiExec.exe /X{90140000-001B-040C-0000-0000000FF1CE}
                                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
                                      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
                                      Mozilla Firefox (3.6.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                      MSFN Codec Pack 5.4-->rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\codec.inf, DefaultUninstall,3
                                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                                      NTRConnect-->MsiExec.exe /X{549514BF-2BDA-422B-9134-67B5A79C2487}
                                      Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
                                      PHOTOfunSTUDIO -viewer--->C:\Program Files\InstallShield Installation Information\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}\setup.exe -runfromtemp -l0x040c -z"Uninstall" -removeonly
                                      QuickTime-->MsiExec.exe /I{3D9892BB-A751-4E48-ADC8-E4289956CE1D}
                                      Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
                                      Security Update pour Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                                      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                                      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                                      Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
                                      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                                      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                                      ZHPDiag 1.26-->"C:\Program Files\ZHPDiag\unins000.exe"

                                      Securitycenter WMI appears to be broken

                                      ======System event log======

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 7035
                                      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexion automatique d'accès distant.

                                      Record Number: 1973
                                      Source Name: Service Control Manager
                                      Time Written: 20100831103252.000000+120
                                      Event Type: Informations
                                      User: AUTORITE NT\SYSTEM

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 7035
                                      Message: Un contrôle Démarrer a correctement été envoyé au service PCANDIS5 NDIS Protocol Driver.

                                      Record Number: 1972
                                      Source Name: Service Control Manager
                                      Time Written: 20100831103252.000000+120
                                      Event Type: Informations
                                      User: 776AB144BD634F8\Administrateur

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 7036
                                      Message: Le service Explorateur d'ordinateur est entré dans l'état : en cours d'exécution.

                                      Record Number: 1971
                                      Source Name: Service Control Manager
                                      Time Written: 20100831103252.000000+120
                                      Event Type: Informations
                                      User:

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 7035
                                      Message: Un contrôle Démarrer a correctement été envoyé au service Explorateur d'ordinateur.

                                      Record Number: 1970
                                      Source Name: Service Control Manager
                                      Time Written: 20100831103252.000000+120
                                      Event Type: Informations
                                      User: AUTORITE NT\SYSTEM

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 7036
                                      Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

                                      Record Number: 1969
                                      Source Name: Service Control Manager
                                      Time Written: 20100831103252.000000+120
                                      Event Type: Informations
                                      User:

                                      =====Application event log=====

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 1042
                                      Message:
                                      Record Number: 140
                                      Source Name: MsiInstaller
                                      Time Written: 20100731034428.000000+120
                                      Event Type: Informations
                                      User: AUTORITE NT\SYSTEM

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 1033
                                      Message:
                                      Record Number: 139
                                      Source Name: MsiInstaller
                                      Time Written: 20100731034428.000000+120
                                      Event Type: Informations
                                      User: 776AB144BD634F8\Administrateur

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 11707
                                      Message:
                                      Record Number: 138
                                      Source Name: MsiInstaller
                                      Time Written: 20100731034428.000000+120
                                      Event Type: Informations
                                      User: 776AB144BD634F8\Administrateur

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 1040
                                      Message:
                                      Record Number: 137
                                      Source Name: MsiInstaller
                                      Time Written: 20100731034427.000000+120
                                      Event Type: Informations
                                      User: 776AB144BD634F8\Administrateur

                                      Computer Name: 776AB144BD634F8
                                      Event Code: 1042
                                      Message:
                                      Record Number: 136
                                      Source Name: MsiInstaller
                                      Time Written: 20100731034425.000000+120
                                      Event Type: Informations
                                      User: AUTORITE NT\SYSTEM

                                      ======Environment variables======

                                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                                      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
                                      "windir"=%SystemRoot%
                                      "FP_NO_HOST_CHECK"=NO
                                      "OS"=Windows_NT
                                      "PROCESSOR_ARCHITECTURE"=x86
                                      "PROCESSOR_LEVEL"=15
                                      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
                                      "PROCESSOR_REVISION"=0409
                                      "NUMBER_OF_PROCESSORS"=1
                                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                      "TEMP"=%SystemRoot%\TEMP
                                      "TMP"=%SystemRoot%\TEMP
                                      "asl.log"=Destination=file;OnFirstLog=command,environment,parent
                                      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                                      -----------------EOF-----------------
                                      0
                                      1. Contributeur sécurité
                                        Télécharge Rsit:outil de diagnostique

                                        http://images.malwareremoval.com/random/RSIT.exe

                                        random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

                                        Double-clique sur RSIT.exe afin de lancer RSIT.

                                        Clique Continue à l'écran Disclaimer.

                                        Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                                        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                                        Poste le contenu de log.txt (<<qui sera affiché)
                                        ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                                        NB : Les rapports sont sauvegardés dans le dossier C:\rsit

                                        Tutoriel pour t'aider

                                        https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm

                                        si le rapport ne passe pas sur le forum à cause de sa longueur envoie-le sur : cijoint

                                        http://www.cijoint.fr/

                                        fais parcourir ,

                                        puis envoie le fichier.

                                        renvoie le lien dans ta prochaine réponse .
                                        0
                                        1. c bon suppression et redemarage ok le rapport... : Malwarebytes' Anti-Malware 1.46
                                          www.malwarebytes.org

                                          Version de la base de données: 4806

                                          Windows 5.1.2600 Service Pack 3
                                          Internet Explorer 8.0.6001.18702

                                          12/10/2010 23:22:21
                                          mbam-log-2010-10-12 (23-22-21).txt

                                          Type d'examen: Examen rapide
                                          Elément(s) analysé(s): 124546
                                          Temps écoulé: 6 minute(s), 2 seconde(s)

                                          Processus mémoire infecté(s): 0
                                          Module(s) mémoire infecté(s): 1
                                          Clé(s) du Registre infectée(s): 5
                                          Valeur(s) du Registre infectée(s): 0
                                          Elément(s) de données du Registre infecté(s): 1
                                          Dossier(s) infecté(s): 0
                                          Fichier(s) infecté(s): 5

                                          Processus mémoire infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Module(s) mémoire infecté(s):
                                          C:\WINDOWS\system32\D3DCompiler_3932.dll (Trojan.Tracur) -> Delete on reboot.

                                          Clé(s) du Registre infectée(s):
                                          HKEY_CLASSES_ROOT\CLSID\{27cf6097-cca4-45c3-86b4-a3cded54da7e} (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{27cf6097-cca4-45c3-86b4-a3cded54da7e} (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{27cf6097-cca4-45c3-86b4-a3cded54da7e} (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27cf6097-cca4-45c3-86b4-a3cded54da7e} (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.

                                          Valeur(s) du Registre infectée(s):
                                          (Aucun élément nuisible détecté)

                                          Elément(s) de données du Registre infecté(s):
                                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                                          Dossier(s) infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Fichier(s) infecté(s):
                                          C:\WINDOWS\system32\D3DCompiler_3932.dll (Trojan.Tracur) -> Delete on reboot.
                                          C:\WINDOWS\system32\13.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          C:\WINDOWS\system32\2E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          C:\WINDOWS\system32\dmstyle32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          C:\WINDOWS\system32\sl898697840 (Trojan.Tracur) -> Quarantined and deleted successfully.
                                          0
                                          • 1
                                          • 2