[registre]impossible de supprimer Eorezo

bonjour,
novice dans les forums j'espère ne pas me tromper.Ma fille à installé EoRezo(eoweather,eorss eocomputer eoclock...) je les ai désinstallé mais
ils apparraissent toujours dans le registre.au démarrage ad watch me signale des modifications de registre corespondant aux logiciels eorezo et partgluehold roam soit 5 modifications soit des modifications qui ne s'arretent pas + de1000 si je ne déesctive pas adwatch.Mon pc est lent au démarrage depuis.Pouvez vous m'aider?
par avance merci
Configuration: Champ	Valeur
Ordinateur	
Système d'exploitation	Microsoft Windows XP Professional
Service Pack du système	Service Pack 2
DirectX	4.09.00.0904 (DirectX 9.0c)
Nom du système	CHAUVE-81C05RRV
Nom de l'utilisateur	stephane
	
Carte mère	
Type de processeur	AMD Athlon XP, 1800 MHz (13.5 x 133) 2200+
Nom de la carte mère	Asus A7N8X-E Deluxe  (5 PCI, 1 AGP Pro, 1 WiFi, 3 DDR DIMM, Audio, Gigabit LAN)
Chipset de la carte mère	nVIDIA nForce2 Ultra 400
Mémoire système	1024 Mo  (PC3200 DDR SDRAM)
Type de BIOS	Award (11/14/03)
Port de communication	Port de communication (COM1)
Port de communication	Port de communication (COM2)
Port de communication	Port imprimante (LPT1)
	
Moniteur	
Carte vidéo	NVIDIA GeForce2 GTS/GeForce2 Pro (Microsoft Corporation)  (64 Mo)
Accélérateur 3D	nVIDIA GeForce2 GTS
Moniteur	Maxdata Belinea 10 60 55  [19" CRT]  (1335200918)
	
Multimédia	
Carte audio	nVIDIA MCP2 - Audio Codec Interface
Carte audio	nVIDIA MCP2 - Audio Processing Unit (Dolby Digital)
	
Stockage	
Contrôleur IDE	NVIDIA nForce2 IDE Controller
Lecteur de disquettes	Lecteur de disquettes
Disque dur	Maxtor 6Y160P0  (160 Go, 7200 RPM, Ultra-ATA/133)
Lecteur optique	SAMSUNG CD-R/RW SW-252B  (52x/24x/52x CD-RW)
Lecteur optique	TOSHIBA DVD-ROM SD-M1402  (12x/40x DVD-ROM)
État des disques durs SMART	OK
	
Partitions	
C: (NTFS)	31063 Mo (20158 Mo libre)
D: (NTFS)	125264 Mo (94659 Mo libre)
Taille totale	152.7 Go (112.1 Go libre)
	
Entrée	
Clavier	Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2
Souris	Logitech-compatible Mouse PS/2
	
Réseau	
Carte réseau	NVIDIA nForce MCP Networking Controller  (82.253.74.53)
	
Périphériques	
Imprimante	Canon i550
Contrôleur USB1	nVIDIA MCP2 - OHCI USB Controller
Contrôleur USB1	nVIDIA MCP2 - OHCI USB Controller
Contrôleur USB2	nVIDIA MCP2 - EHCI USB 2.0 Controller
Périphérique USB	CanoScan LiDE 20/N670U/N676U
Périphérique USB	Logitech Microphone (Pro 4000)
Périphérique USB	Logitech QuickCam Pro 4000
Périphérique USB	Logitech USB Camera (Pro 4000)

83 réponses

Résumé de la discussion

Le problème porte sur des restes de EoRezo et des malwares associés qui réapparaissent au démarrage après désinstallation, entraînant des modifications répétées du registre et un ralenti du PC. Des solutions proposées incluent la désactivation des composants via regsvr32 /u pour plusieurs DLL d’EoRezo et la suppression manuelle du dossier C:\Program Files\EoRezo, éventuellement en mode sans échec. D'autres réponses recommandent des outils comme HijackThis et SmitfraudFix, ou des suites anti-pub comme Ad-Aware SE et Spybot, pour identifier et supprimer les entrées d’autorun et les fichiers persistants. Une observation fréquente est que les symptômes peuvent varier entre sessions, ce qui justifie une vérification croisée avec HijackThis et des nettoyages ciblés des entrées Run et des composants similaires.

Bobot (l’IA à votre service)
  1. Logfile of HijackThis v1.99.1
    Scan saved at 21:03:13, on 23/06/2009
    Platform: Unknown Windows (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16851)

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Users\Rem's\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.bin
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Windows\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Axon Data\AxCrypt\1.6.4.4\AxCrypt.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Users\Rem's\AppData\Local\Temp\Rar$EX01.970\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2080201
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [SoftwareHelper] C:\Users\Rem's\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe -runonce
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O13 - Gopher Prefix:
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    1. euh pardon : http://tragmaster.blogspot.com/
      1. bonjour,moi aussi j'etais envahi et après moultes tentatives avec l'aide des forums ,j'ai fait une restauration et cette sal...ie est partie pour l'instant!!! bonne chance
    2. télécharger le Uninstall ! http://tragmasteur.fr.gd/T-e2-l-e2-chargement.htm
      1. Bonsoir,

        Eorezo vient de creer BEAUCOUP de pb chez un un mes amis ... c est une VRAIE SALOPERIE

        faites circuler l info au maximum sur tous les forums et sur google

        je ne citerai pas l adesse mentionnée + haut , mais un bon scud en justice leur ferait pas assez de mal pour celui qu il genere tous les jours
        1. http://tragmasteur.fr.gd/T-e2-l-e2-chargement.htm pour désinstaller
      2. Bonsoir,

        Eorezo vient de creer BEAUCOUP de pb chez un un mes amis ... c est une VRAIE SALOPERIE

        faites circuler l info au maximum sur tous les forums et sur google

        je ne citerai pas l adesse mentionnée + haut , mais un bon scud en justice leur ferait pas assez de mal pour celui qu il genere tous les jours
        1. Contributeur sécurité
          Bonsoir,

          1°- Dans quel répertoire se trouve ton EoRezo ==> regarde dans "Poste de travail" > "C:\" > "Program Files" ?

          2°- Si je te donne cette ligne :
          regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv\EoRezoBHO.dll"
          Sais-tu en faire un copier/coller dans un document Word par exemple ?

          Al.
          1. Bonsoir, comme casquette j'ai EoreZo qui est arrivé sur mon ordi je ne sais comment et je n'arrive pas à le retirer. J'ai esseyé de suivre tes indications mais je comprend pas, désolé. Pourrez-tu me réxpliqué plus en dérail stp
            1. Contributeur sécurité
              Salut lena

              Cit. « ...EoRezo interfere à chaque fois que j'allume mon pc,c'est comme si il s'agissait d'un virus, il fonctionne de la même façon,mon systéme est ralentit,et en plus des fenêtres publicitaires s'ouvrent de façon intempestive »

              C'est nomal, EoRezo est une régie publicitaire !

              Applique la procédure du post # 83
              Ensuite arrête puis redémarre le PC.

              Bonne chance
              Al.
              1. Bonjour,j'ai également un probléme avec EoRezo,une personne,qui se trouve être un technicien informatique m'a conseillé de télécharger VLC,en m'assurant que je pouvais lire tous mes fichiers en téléchargeant cet unique codec,mais depuis EoRezo interfere à chaque fois que j'allume mon pc,c'est comme si il s'agissait d'un virus, il fonctionne de la même façon,mon systéme est ralentit,et en plus des fenêtres publicitaires s'ouvrent de façon intempestive,exactement comme la fois ou j'avais un trojan!
                Qu'en pensez-vous???
                Merci...
                1. Contributeur sécurité
                  1°- Je dis bonjour.
                  2°- J'ai HORREUR que l'on squatte le topic d'un autre internaute !
                  Est-ce que j'entre chez toi sans frapper ?? Si toi tu essaies un jour de le faire chez moi, mets un gilet pare-balles et un casque intégral.
                  3°- Cit. « est-ce que c'était ca qu'il fallait faire ? »
                  ==> si c'est pour couper l'alimentation de ton PC; je dirais NON, ce n'est pas ce qu'il fallait faire.
                  4°- Mais que veux-tu faire ?
                  Que se passe-t-il ?
                  Où as-tu mal ? ---> ou plus précisément, quels soucis as-tu avec ton PC ?
                  Reçois-tu des messages d'erreurs ? Lesquels ?
                  Etc.

                  Le thème de ce topic étant "Suppression de eoRezo", voici comment faire:
                  a)- "démarrer"/"exécuter", et coller la ligne suivante :
                  regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv\EoRezoBHO.dll" , puis clic sur [OK]
                  Coller ensuite celle-ci regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv , puis clic sur [OK]
                  Coller ensuite celle-ci regsvr32 /u "C:\PROGRAM FILES\eoRezo , puis clic sur [OK]
                  (Valide par [Entrée = OK] à chaque ligne , peu importe le message que tu obtiendras).
                  b)- Ensuite essaye de supprimer à nouveau ce dossier eoRezo qui se situe en C:\PROGRAM FILES\
                  Si ça ne marche pas, supprime directement le dossier eoRezo en mode sans échec.
                  < http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >

                  PS: Ton OS installé est-il VISTA ?

                  Bonne chance
                  Al.
                  1. Logfile of HijackThis v1.99.1
                    Scan saved at 09:33:58, on 04/04/2008
                    Platform: Unknown Windows (WinNT 6.00.1904)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16609)

                    Running processes:
                    c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                    C:\Program Files\HP\QuickPlay\QPService.exe
                    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Program Files\GRISOFT\AVG7\avgcc.exe
                    C:\Program Files\EoRezo\EoEngine.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\Program Files\WinZip\WZQKPICK.EXE
                    C:\Windows\system32\wbem\unsecapp.exe
                    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                    C:\Program Files\GRISOFT\AVG7\avgw.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\WinRAR\WinRAR.exe
                    C:\hijackthis\HijackThis.exe
                    C:\Windows\system32\NOTEPAD.EXE

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                    O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                    O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                    O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                    O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
                    O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE
                    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
                    O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\Its Label\ItsTV\ItsTV.exe"
                    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
                    O4 - Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
                    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                    O11 - Options group: [INTERNATIONAL] International*
                    O13 - Gopher Prefix:
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                    O20 - AppInit_DLLs: APSHook.dll
                    O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
                    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
                    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

                    est-ce que c'était ca qu'il fallait faire ?
                    1. Adobe Reader 6.0 - Français
                      All To MP3 Converter 1.6
                      Anti-Hacker
                      Anti-Virus
                      ArcSoft ShowBiz 2
                      ATI Control Panel
                      ATI Display Driver
                      AVS Audio Tools version 4.1
                      Connexion Facile à Internet
                      Correctif pour DirectX - KB825116
                      Correctif Windows XP - KB821557
                      Correctif Windows XP - KB823559
                      Correctif Windows XP - KB824146
                      Correctif Windows XP (SP2) Q327979
                      Correctif Windows XP (SP2) Q328310
                      Correctif Windows XP (SP2) Q329112
                      Correctif Windows XP (SP2) Q329170
                      Correctif Windows XP (SP2) q329623
                      Correctif Windows XP (SP2) Q329909
                      Correctif Windows XP (SP2) Q331953
                      Correctif Windows XP (SP2) Q810565
                      Correctif Windows XP (SP2) Q810577
                      Correctif Windows XP (SP2) Q810833
                      Correctif Windows XP (SP2) Q811789
                      Correctif Windows XP (SP2) Q814033
                      Correctif Windows XP (SP2) Q814995
                      Correctif Windows XP (SP2) Q815485
                      Correctif Windows XP (SP2) Q817287
                      Correctif Windows XP (SP2) Q817606
                      HijackThis 1.99.1
                      HP Deskjet Preloaded Printer Drivers
                      HP Photo and Imaging 2.0 - Photosmart Cameras
                      HP PSC & OfficeJet 3.0
                      HP Software Update
                      Intel(R) Extreme Graphics Driver
                      Internet Explorer Q828750
                      InterVideo WinDVD Player
                      Java 2 Runtime Environment, SE v1.4.2
                      KBD
                      Macromedia Flash Player 8
                      Memories Disc Creator 2.0
                      Microsoft .NET Framework 1.1
                      Microsoft .NET Framework 1.1 French Language Pack
                      NVIDIA GART Driver
                      Outlook Express Update Q330994
                      Package du correctif Windows XP [voir Q329115 pour plus de détails]
                      Package du correctif Windows XP [voir q329256 pour plus de détails]
                      Package du correctif Windows XP [voir Q329390 pour plus de détails]
                      Package du correctif Windows XP [voir Q329834 pour plus de détails]
                      Package du correctif Windows XP [voir Q331958 pour plus de détails]
                      PC CAMERA DATA SOURCE(6029)1.0(32-32)
                      Photo et imagerie HP 3.1
                      Photosmart 140,240,7200,7600,7700,7900 Series
                      PS2
                      Python 2.2 combined Win32 extensions
                      Python 2.2.1
                      RecordNow!
                      Sonic Update Manager
                      Sound Blaster Extigy
                      Thème Nature 2 Nature
                      Thème Québec
                      Trust 150 Spacecam Portable
                      Windows Live Messenger
                      Windows Live Sign-in Assistant
                      1. Salut

                        Renseigne toi dans la section materiel, ils sont plus competent que moi dans ce domaine. Par contre, si tu n as pas de réponse, tu peux revenir sans problemes.

                        Ravi que tes soucis virus soit resolus. Essai de poster dans l autre partie du forum et si vraiment tu n'as pas de réponses, repostes sur ce topic avec plaisir.

                        Bonne soirée
                        1. bonsoir régis,
                          ok pour le pare feu tu as raison.autrement plus de problème mais je voulais savoir si je pouvais O/C mon proc et jusqu'où en fonction de mon matériel.J'ai lu un sujet sur le possésseur d'un amd xp 2200 poussé de 1800 mhz à 2200MHz avec la même carte mere que moi.J'arrive à le monter à1920 sans hausse de température importante mais je ne suis pas sur de mes réglages et je ne veux pas faire de bétise.Ce n'est pas pressé mais si je pouvais gagner un peu plus de puissance pourquoi pas.une derniere question concerne ma carte graphique, je ne joue pas trop et ma fille joue avec des jeux pas trop gourmand ,mais je me demande si je ne gagnerais pas en fluidité et rapidité en la changeant(sans mettre un prix fou)Voila comme tu le vois encore des questions
                          merci et A+
                          1. Salut Stéphane,

                            Kaspersky integre un pare feu?

                            A la place d ad watch qui surveille les modifications du registre, autant detenir un pare feu qui permettra a toi meme, de refuser et d accepter les processus a acceder au net.De la, le pare feu pourra bloques les intrusions.

                            Pour tes autres soucis, quels sont ils?

                            a+
                            1. salut régis,
                              juste un petit mot pour te dire que tout est en ordre sur mon pc,merci encore.Peux tu me conseiller un logiciel pour remplacer Ad-Watch et si c'est vraiment utile.Pour l'overclockink je dois me rendre sur quel forum
                              A+
                              stéphane
                              1. Salut

                                ah voila , enfin....

                                Tu as cette version Ad-Aware SE Build 1.05 , desinstalles la !

                                Installes celle ci
                                Ad-Aware SE 1.06 <<nouvelle version.
                                http://www.lavasoftusa.com/software/adaware/
                                -Une aide:
                                http://www.tutopat.com/viewtopic.php?t=1191
                                - installe le patch français, tu pourras le trouver ici:
                                http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
                                et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation).
                                http://pageperso.aol.fr/balltrap34/adawrevid.asf

                                a+
                                1. voila le rapport
                                  Ad-Aware SE Build 1.05
                                  Fichier journal créé le :dimanche 12 février 2006 19:09:39
                                  Utilisation du fichier de définitions :SE1R91 08.02.2006
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Références détectées lors de l’analyse :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  MRU List(Index TAC :0):15 Nombre total de références
                                  Tracking Cookie(Index TAC :3):1 Nombre total de références
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Ad-Aware SE Settings
                                  ===========================
                                  Définir : Rechercher les entrées à risque négligeable
                                  Définir : Mode sécurisé (tjrs demander confirm.)
                                  Définir : Analyser les processus actifs
                                  Définir : Scan registry
                                  Définir : Analyser en profondeur le registre
                                  Définir : Analyser mes favoris IE pour rech. URL interdites
                                  Définir : Analyser mon fichier Hosts

                                  Extended Ad-Aware SE Settings
                                  ===========================
                                  Définir : Décharger les modules et les processus reconnus pendant l’analyse
                                  Définir : Ignorer les fichiers fractionnés lors de l’analyse des archives .CAB
                                  Définir : Anal. reg. pr tous utili. et non pr utili. actuel uniqmnt
                                  Définir : Toujours essayer de décharger les modules avant la suppression
                                  Définir : Lors de la suppression, décharger l’Explorateur et IE si nécessaire
                                  Définir : Perm. Win. supp. fich. en cours au proch. démar.
                                  Définir : Supprimer les objets en quarantaine après la restauration
                                  Définir : Forcer le blocage des fenêtres publicitaires
                                  Définir : Sélec. auto. objets problématiques dans listes de résultats
                                  Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
                                  Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
                                  Définir : Inclure un récapitulatif des références dans le fichier journal
                                  Définir : Inclure les détails des données ADS dans le fichier journal
                                  Définir : Afficher l’écran d’accueil
                                  Définir : Sauvegarder le fichier de définitions utilisé avant d’effectuer une mise à jour
                                  Définir : Émettre un son à la fin de l’analyse en cas de détection d'objets critiques

                                  12-02-2006 19:09:39 - L’analyse a démarré. (Analyse complète du système)

                                  MRU List Objet reconnu !
                                  Emplacement : : software\microsoft\direct3d\mostrecentapplication
                                  Description : most recent application to use microsoft direct3d

                                  MRU List Objet reconnu !
                                  Emplacement : : software\microsoft\direct3d\mostrecentapplication
                                  Description : most recent application to use microsoft direct X

                                  MRU List Objet reconnu !
                                  Emplacement : : software\microsoft\directdraw\mostrecentapplication
                                  Description : most recent application to use microsoft directdraw

                                  MRU List Objet reconnu !
                                  Emplacement : : .DEFAULT\software\microsoft\mediaplayer\preferences
                                  Description : last playlist loaded in microsoft windows media player

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-18\software\microsoft\mediaplayer\preferences
                                  Description : last playlist loaded in microsoft windows media player

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-20\software\microsoft\mediaplayer\preferences
                                  Description : last playlist loaded in microsoft windows media player

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\mediaplayer\preferences
                                  Description : last playlist loaded in microsoft windows media player

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\microsoft management console\recent file list
                                  Description : list of recent snap-ins used in the microsoft management console

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\search assistant\acmru
                                  Description : list of recent search terms used with the search assistant

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\applets\regedit
                                  Description : last key accessed using the microsoft registry editor

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
                                  Description : list of recent programs opened

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
                                  Description : list of recently saved files, stored according to file extension

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\recentdocs
                                  Description : list of recent documents opened

                                  MRU List Objet reconnu !
                                  Emplacement : : .DEFAULT\software\microsoft\windows media\wmsdk\general
                                  Description : windows media sdk

                                  MRU List Objet reconnu !
                                  Emplacement : : S-1-5-18\software\microsoft\windows media\wmsdk\general
                                  Description : windows media sdk

                                  Affichage des processus en cours d'exécution
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  #:1 [smss.exe]
                                  FilePath : \SystemRoot\System32\
                                  ProcessID : 296
                                  ThreadCreationTime : 12-02-2006 18:07:21
                                  BasePriority : Normal

                                  #:2 [csrss.exe]
                                  FilePath : \??\C:\WINDOWS\system32\
                                  ProcessID : 408
                                  ThreadCreationTime : 12-02-2006 18:07:36
                                  BasePriority : Normal

                                  #:3 [winlogon.exe]
                                  FilePath : \??\C:\WINDOWS\system32\
                                  ProcessID : 432
                                  ThreadCreationTime : 12-02-2006 18:07:38
                                  BasePriority : High

                                  #:4 [services.exe]
                                  FilePath : C:\WINDOWS\system32\
                                  ProcessID : 480
                                  ThreadCreationTime : 12-02-2006 18:07:42
                                  BasePriority : Normal
                                  FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 5.1.2600.2180
                                  ProductName : Système d'exploitation Microsoft® Windows®
                                  CompanyName : Microsoft Corporation
                                  FileDescription : Applications Services et Contrôleur
                                  InternalName : services.exe
                                  LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                                  OriginalFilename : services.exe

                                  #:5 [lsass.exe]
                                  FilePath : C:\WINDOWS\system32\
                                  ProcessID : 492
                                  ThreadCreationTime : 12-02-2006 18:07:43
                                  BasePriority : Normal
                                  FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 5.1.2600.2180
                                  ProductName : Microsoft® Windows® Operating System
                                  CompanyName : Microsoft Corporation
                                  FileDescription : LSA Shell (Export Version)
                                  InternalName : lsass.exe
                                  LegalCopyright : © Microsoft Corporation. All rights reserved.
                                  OriginalFilename : lsass.exe

                                  #:6 [svchost.exe]
                                  FilePath : C:\WINDOWS\system32\
                                  ProcessID : 644
                                  ThreadCreationTime : 12-02-2006 18:07:45
                                  BasePriority : Normal
                                  FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 5.1.2600.2180
                                  ProductName : Microsoft® Windows® Operating System
                                  CompanyName : Microsoft Corporation
                                  FileDescription : Generic Host Process for Win32 Services
                                  InternalName : svchost.exe
                                  LegalCopyright : © Microsoft Corporation. All rights reserved.
                                  OriginalFilename : svchost.exe

                                  #:7 [svchost.exe]
                                  FilePath : C:\WINDOWS\system32\
                                  ProcessID : 704
                                  ThreadCreationTime : 12-02-2006 18:07:47
                                  BasePriority : Normal
                                  FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 5.1.2600.2180
                                  ProductName : Microsoft® Windows® Operating System
                                  CompanyName : Microsoft Corporation
                                  FileDescription : Generic Host Process for Win32 Services
                                  InternalName : svchost.exe
                                  LegalCopyright : © Microsoft Corporation. All rights reserved.
                                  OriginalFilename : svchost.exe

                                  #:8 [svchost.exe]
                                  FilePath : C:\WINDOWS\system32\
                                  ProcessID : 772
                                  ThreadCreationTime : 12-02-2006 18:07:49
                                  BasePriority : Normal
                                  FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 5.1.2600.2180
                                  ProductName : Microsoft® Windows® Operating System
                                  CompanyName : Microsoft Corporation
                                  FileDescription : Generic Host Process for Win32 Services
                                  InternalName : svchost.exe
                                  LegalCopyright : © Microsoft Corporation. All rights reserved.
                                  OriginalFilename : svchost.exe

                                  #:9 [wrsssdk.exe]
                                  FilePath : C:\Program Files\Webroot\Spy Sweeper\
                                  ProcessID : 808
                                  ThreadCreationTime : 12-02-2006 18:07:49
                                  BasePriority : Normal
                                  FileVersion : 2,0,9,509
                                  ProductVersion : 2, 0
                                  ProductName : Spy Sweeper SDK
                                  CompanyName : Webroot Software, Inc.
                                  FileDescription : Spy Sweeper SDK
                                  LegalCopyright : Copyright (C) 2002 - 2005, All Rights Reserved.
                                  LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
                                  OriginalFilename : SpySweeper.exe

                                  #:10 [explorer.exe]
                                  FilePath : C:\WINDOWS\
                                  ProcessID : 944
                                  ThreadCreationTime : 12-02-2006 18:08:03
                                  BasePriority : Normal
                                  FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                                  ProductVersion : 6.00.2900.2180
                                  ProductName : Système d'exploitation Microsoft® Windows®
                                  CompanyName : Microsoft Corporation
                                  FileDescription : Explorateur Windows
                                  InternalName : explorer
                                  LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                                  OriginalFilename : EXPLORER.EXE

                                  #:11 [ad-aware.exe]
                                  FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Professional\
                                  ProcessID : 1028
                                  ThreadCreationTime : 12-02-2006 18:08:19
                                  BasePriority : Normal
                                  FileVersion : 6.2.0.208
                                  ProductVersion : VI.Second Edition
                                  ProductName : Lavasoft Ad-Aware SE
                                  CompanyName : Lavasoft Sweden
                                  FileDescription : Ad-Aware SE Core application
                                  InternalName : Ad-Aware.exe
                                  LegalCopyright : Copyright © Lavasoft Sweden
                                  OriginalFilename : Ad-Aware.exe
                                  Comments : All Rights Reserved

                                  Résultat de l’analyse de la mémoire :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 15

                                  Analyse du registre démarrée
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat de l’analyse du registre :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 15

                                  Analyse approfondie du registre démarrée
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat de l’analyse approfondie du registre :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 15

                                  Analyse des cookies de suivi lancée
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat de l’analyse des cookies de suivi :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 15

                                  Analyse et examen approfondis des fichiers (C:)
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Tracking Cookie Objet reconnu !
                                  Type : IECache Entry
                                  Données : hansa@weborama[2].txt
                                  Catégorie : Data Miner
                                  Commentaire :
                                  Valeur : C:\Documents and Settings\hansa\Cookies\hansa@weborama[2].txt

                                  Résultat de l’analyse du disque pour C:\
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 16

                                  Analyse et examen approfondis des fichiers (D:)
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat de l’analyse du disque pour D:\
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 16

                                  Analyse du fichier Hosts…...
                                  Emplacement du fichier Hosts :"C:\WINDOWS\system32\drivers\etc\hosts".
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat d’analyse du fichier Hosts :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  1 entrées analysées.
                                  Nouv. obj. critiques :0
                                  Objets détectés jusqu'à présent : 16

                                  Analyses conditionnelles en cours...
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                  Résultat d’analyse conditionnelle :
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Nouv. obj. critiques : 0
                                  Objets détectés jusqu'à présent : 16

                                  19:24:09 Analyse terminée

                                  Récap. de cette anal.
                                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                  Durée tot. analyse :00:14:30.531
                                  Objets analysés :121414
                                  Objets identifiés :1
                                  Objets ignorés :0
                                  Nouv. obj. critiques :1
                                  1. salut

                                    passe en sans echec et lance ad aware, sauvegarde le rapport et donne le moi

                                    a+
                                    1. salut,
                                      voilà le résultat:
                                      Rapport fait à 18:37:04,29 le 12/02/2006

                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\Documents and Settings\Administrateur\Application Data

                                      30/01/2006 13:33 <REP> Lavasoft
                                      25/11/2005 12:11 62 desktop.ini
                                      25/11/2005 12:11 <REP> ..
                                      25/11/2005 12:11 <REP> Microsoft
                                      25/11/2005 12:11 <REP> .
                                      1 fichier(s) 62 octets
                                      4 R‚p(s) 20849938432 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\Documents and Settings\All Users\Application Data

                                      08/02/2006 13:11 <REP> SecTaskMan
                                      25/01/2006 18:33 <REP> SSScanWizard
                                      25/01/2006 18:33 <REP> SSScanAppDataDir
                                      24/01/2006 08:49 <REP> Spybot - Search & Destroy
                                      31/12/2005 11:57 <REP> InstallShield
                                      31/12/2005 11:55 <REP> Sonic
                                      31/12/2005 11:49 <REP> Roxio
                                      17/12/2005 18:01 <REP> Trymedia
                                      15/12/2005 09:36 <REP> Symantec
                                      08/12/2005 17:23 <REP> Windows Genuine Advantage
                                      04/12/2005 19:30 <REP> Zylom
                                      31/10/2005 11:54 <REP> ScanSoft
                                      19/10/2005 11:04 <REP> MSN6
                                      18/10/2005 09:15 <REP> Kaspersky Anti-Virus Personal
                                      17/10/2005 18:50 62 desktop.ini
                                      17/10/2005 18:49 <REP> Microsoft
                                      17/10/2005 18:49 <REP> .
                                      17/10/2005 18:49 <REP> ..
                                      1 fichier(s) 62 octets
                                      17 R‚p(s) 20849934336 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\Documents and Settings\Default User\Application Data

                                      17/10/2005 18:50 62 desktop.ini
                                      17/10/2005 18:49 <REP> ..
                                      17/10/2005 18:49 <REP> Microsoft
                                      17/10/2005 18:49 <REP> .
                                      1 fichier(s) 62 octets
                                      3 R‚p(s) 20849934336 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\Documents and Settings\hansa\Application Data

                                      04/02/2006 13:17 <REP> ScanSoft
                                      04/02/2006 12:44 <REP> ArcSoft
                                      02/02/2006 16:54 <REP> SuperAdBlocker.com
                                      23/01/2006 10:10 <REP> OrphansRemover
                                      11/01/2006 18:53 <REP> metafastfilm
                                      11/01/2006 18:46 3601 bhrslog.txt
                                      31/12/2005 12:03 <REP> Roxio
                                      17/12/2005 13:26 <REP> Real
                                      14/12/2005 19:57 <REP> OpenOffice.org2
                                      04/12/2005 19:30 <REP> Zylom
                                      15/11/2005 18:57 <REP> Webroot
                                      12/11/2005 19:52 <REP> MSN6
                                      09/11/2005 20:51 <REP> Canon
                                      09/11/2005 20:46 <REP> XnView
                                      08/11/2005 18:37 <REP> Lavasoft
                                      05/11/2005 17:15 <REP> Sun
                                      27/10/2005 14:14 <REP> Adobe
                                      19/10/2005 17:29 <REP> Macromedia
                                      19/10/2005 10:41 <REP> Free Download Manager
                                      19/10/2005 10:22 <REP> Thunderbird
                                      19/10/2005 10:10 <REP> Mozilla
                                      19/10/2005 10:06 <REP> WinPatrol
                                      17/10/2005 19:35 <REP> Identities
                                      17/10/2005 19:35 62 desktop.ini
                                      17/10/2005 19:35 <REP> ..
                                      17/10/2005 19:35 <REP> .
                                      17/10/2005 19:35 <REP> Microsoft
                                      2 fichier(s) 3663 octets
                                      25 R‚p(s) 20849934336 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\Documents and Settings\stephane\Application Data

                                      03/02/2006 19:18 <REP> Webroot
                                      02/02/2006 11:21 <REP> PopUpSentry.com
                                      02/02/2006 10:13 <REP> SuperAdBlocker.com
                                      25/01/2006 19:27 <REP> Canon
                                      25/01/2006 18:33 <REP> ScanSoft
                                      31/12/2005 12:00 <REP> Roxio
                                      15/12/2005 09:36 <REP> IsolatedStorage
                                      08/12/2005 16:40 <REP> Real
                                      05/12/2005 12:25 <REP> OrphansRemover
                                      20/11/2005 17:08 <REP> vlc
                                      14/11/2005 12:55 <REP> Google
                                      07/11/2005 16:36 <REP> Media Player Classic
                                      04/11/2005 12:52 <REP> ArcSoft
                                      31/10/2005 07:58 <REP> Help
                                      26/10/2005 10:21 <REP> Azureus
                                      22/10/2005 10:55 <REP> OpenOffice.org2
                                      20/10/2005 09:56 <REP> Sun
                                      19/10/2005 11:04 <REP> MSN6
                                      19/10/2005 09:51 <REP> WinPatrol
                                      19/10/2005 07:30 <REP> XnView
                                      18/10/2005 12:26 <REP> Talkback
                                      18/10/2005 12:26 <REP> Thunderbird
                                      18/10/2005 12:15 <REP> Mozilla
                                      18/10/2005 09:15 <REP> SpamTest
                                      17/10/2005 19:07 <REP> Identities
                                      17/10/2005 19:07 62 desktop.ini
                                      17/10/2005 19:07 <REP> ..
                                      17/10/2005 19:07 <REP> Microsoft
                                      17/10/2005 19:07 <REP> .
                                      17/10/2005 18:36 <REP> .ABC
                                      17/10/2005 18:35 <REP> Lavasoft
                                      17/10/2005 17:46 <REP> Macromedia
                                      17/10/2005 17:21 <REP> Free Download Manager
                                      17/10/2005 16:51 <REP> Adobe
                                      17/10/2005 16:51 <REP> InterTrust
                                      30/07/2005 06:22 12185 bhrslog.txt
                                      2 fichier(s) 12247 octets
                                      34 R‚p(s) 20849930240 octets libres
                                      ******************************************
                                      Recherche des taches planifiées dans C:\WINDOWS\tasks

                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le num‚ro de s‚rie du volume est 20DC-C99D

                                      R‚pertoire de C:\WINDOWS\Tasks

                                      17/10/2005 19:02 6 SA.DAT
                                      17/10/2005 19:01 65 desktop.ini
                                      17/10/2005 19:01 <REP> ..
                                      17/10/2005 19:01 <REP> .
                                      2 fichier(s) 71 octets
                                      2 R‚p(s) 20ÿ849ÿ930ÿ240 octets libres

                                      ******************************************
                                      Recherche dans Program files

                                      Le dossier C:\Program Files\C2Media n'existe pas

                                      *************** Fin du rapport ****************

                                      A+
                                      • 1
                                      • 2
                                      • 3
                                      • 4
                                      • 5