[registre]impossible de supprimer Eorezo
novice dans les forums j'espère ne pas me tromper.Ma fille à installé EoRezo(eoweather,eorss eocomputer eoclock...) je les ai désinstallé mais
ils apparraissent toujours dans le registre.au démarrage ad watch me signale des modifications de registre corespondant aux logiciels eorezo et partgluehold roam soit 5 modifications soit des modifications qui ne s'arretent pas + de1000 si je ne déesctive pas adwatch.Mon pc est lent au démarrage depuis.Pouvez vous m'aider?
par avance merci
Configuration: Champ Valeur Ordinateur Système d'exploitation Microsoft Windows XP Professional Service Pack du système Service Pack 2 DirectX 4.09.00.0904 (DirectX 9.0c) Nom du système CHAUVE-81C05RRV Nom de l'utilisateur stephane Carte mère Type de processeur AMD Athlon XP, 1800 MHz (13.5 x 133) 2200+ Nom de la carte mère Asus A7N8X-E Deluxe (5 PCI, 1 AGP Pro, 1 WiFi, 3 DDR DIMM, Audio, Gigabit LAN) Chipset de la carte mère nVIDIA nForce2 Ultra 400 Mémoire système 1024 Mo (PC3200 DDR SDRAM) Type de BIOS Award (11/14/03) Port de communication Port de communication (COM1) Port de communication Port de communication (COM2) Port de communication Port imprimante (LPT1) Moniteur Carte vidéo NVIDIA GeForce2 GTS/GeForce2 Pro (Microsoft Corporation) (64 Mo) Accélérateur 3D nVIDIA GeForce2 GTS Moniteur Maxdata Belinea 10 60 55 [19" CRT] (1335200918) Multimédia Carte audio nVIDIA MCP2 - Audio Codec Interface Carte audio nVIDIA MCP2 - Audio Processing Unit (Dolby Digital) Stockage Contrôleur IDE NVIDIA nForce2 IDE Controller Lecteur de disquettes Lecteur de disquettes Disque dur Maxtor 6Y160P0 (160 Go, 7200 RPM, Ultra-ATA/133) Lecteur optique SAMSUNG CD-R/RW SW-252B (52x/24x/52x CD-RW) Lecteur optique TOSHIBA DVD-ROM SD-M1402 (12x/40x DVD-ROM) État des disques durs SMART OK Partitions C: (NTFS) 31063 Mo (20158 Mo libre) D: (NTFS) 125264 Mo (94659 Mo libre) Taille totale 152.7 Go (112.1 Go libre) Entrée Clavier Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2 Souris Logitech-compatible Mouse PS/2 Réseau Carte réseau NVIDIA nForce MCP Networking Controller (82.253.74.53) Périphériques Imprimante Canon i550 Contrôleur USB1 nVIDIA MCP2 - OHCI USB Controller Contrôleur USB1 nVIDIA MCP2 - OHCI USB Controller Contrôleur USB2 nVIDIA MCP2 - EHCI USB 2.0 Controller Périphérique USB CanoScan LiDE 20/N670U/N676U Périphérique USB Logitech Microphone (Pro 4000) Périphérique USB Logitech QuickCam Pro 4000 Périphérique USB Logitech USB Camera (Pro 4000)
83 réponses
Le problème porte sur des restes de EoRezo et des malwares associés qui réapparaissent au démarrage après désinstallation, entraînant des modifications répétées du registre et un ralenti du PC. Des solutions proposées incluent la désactivation des composants via regsvr32 /u pour plusieurs DLL d’EoRezo et la suppression manuelle du dossier C:\Program Files\EoRezo, éventuellement en mode sans échec. D'autres réponses recommandent des outils comme HijackThis et SmitfraudFix, ou des suites anti-pub comme Ad-Aware SE et Spybot, pour identifier et supprimer les entrées d’autorun et les fichiers persistants. Une observation fréquente est que les symptômes peuvent varier entre sessions, ce qui justifie une vérification croisée avec HijackThis et des nettoyages ciblés des entrées Run et des composants similaires.
-
Logfile of HijackThis v1.99.1
Scan saved at 21:03:13, on 23/06/2009
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16851)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Users\Rem's\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Axon Data\AxCrypt\1.6.4.4\AxCrypt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Users\Rem's\AppData\Local\Temp\Rar$EX01.970\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2080201
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [SoftwareHelper] C:\Users\Rem's\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe -runonce
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -
euh pardon : http://tragmaster.blogspot.com/
-
télécharger le Uninstall ! http://tragmasteur.fr.gd/T-e2-l-e2-chargement.htm
-
Bonsoir,
Eorezo vient de creer BEAUCOUP de pb chez un un mes amis ... c est une VRAIE SALOPERIE
faites circuler l info au maximum sur tous les forums et sur google
je ne citerai pas l adesse mentionnée + haut , mais un bon scud en justice leur ferait pas assez de mal pour celui qu il genere tous les jours -
Bonsoir,
Eorezo vient de creer BEAUCOUP de pb chez un un mes amis ... c est une VRAIE SALOPERIE
faites circuler l info au maximum sur tous les forums et sur google
je ne citerai pas l adesse mentionnée + haut , mais un bon scud en justice leur ferait pas assez de mal pour celui qu il genere tous les jours -
Contributeur sécuritéBonsoir,
1°- Dans quel répertoire se trouve ton EoRezo ==> regarde dans "Poste de travail" > "C:\" > "Program Files" ?
2°- Si je te donne cette ligne :
regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv\EoRezoBHO.dll"
Sais-tu en faire un copier/coller dans un document Word par exemple ?
Al.
-
Bonsoir, comme casquette j'ai EoreZo qui est arrivé sur mon ordi je ne sais comment et je n'arrive pas à le retirer. J'ai esseyé de suivre tes indications mais je comprend pas, désolé. Pourrez-tu me réxpliqué plus en dérail stp
-
Contributeur sécuritéSalut lena
Cit. « ...EoRezo interfere à chaque fois que j'allume mon pc,c'est comme si il s'agissait d'un virus, il fonctionne de la même façon,mon systéme est ralentit,et en plus des fenêtres publicitaires s'ouvrent de façon intempestive »
C'est nomal, EoRezo est une régie publicitaire !
Applique la procédure du post # 83
Ensuite arrête puis redémarre le PC.
Bonne chance
Al. -
Bonjour,j'ai également un probléme avec EoRezo,une personne,qui se trouve être un technicien informatique m'a conseillé de télécharger VLC,en m'assurant que je pouvais lire tous mes fichiers en téléchargeant cet unique codec,mais depuis EoRezo interfere à chaque fois que j'allume mon pc,c'est comme si il s'agissait d'un virus, il fonctionne de la même façon,mon systéme est ralentit,et en plus des fenêtres publicitaires s'ouvrent de façon intempestive,exactement comme la fois ou j'avais un trojan!
Qu'en pensez-vous???
Merci... -
Contributeur sécurité1°- Je dis bonjour.
2°- J'ai HORREUR que l'on squatte le topic d'un autre internaute !
Est-ce que j'entre chez toi sans frapper ?? Si toi tu essaies un jour de le faire chez moi, mets un gilet pare-balles et un casque intégral.
3°- Cit. « est-ce que c'était ca qu'il fallait faire ? »
==> si c'est pour couper l'alimentation de ton PC; je dirais NON, ce n'est pas ce qu'il fallait faire.
4°- Mais que veux-tu faire ?
Que se passe-t-il ?
Où as-tu mal ? ---> ou plus précisément, quels soucis as-tu avec ton PC ?
Reçois-tu des messages d'erreurs ? Lesquels ?
Etc.
Le thème de ce topic étant "Suppression de eoRezo", voici comment faire:
a)- "démarrer"/"exécuter", et coller la ligne suivante :
regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv\EoRezoBHO.dll" , puis clic sur [OK]
Coller ensuite celle-ci regsvr32 /u "C:\PROGRAM FILES\eoRezo\EoAdv , puis clic sur [OK]
Coller ensuite celle-ci regsvr32 /u "C:\PROGRAM FILES\eoRezo , puis clic sur [OK]
(Valide par [Entrée = OK] à chaque ligne , peu importe le message que tu obtiendras).
b)- Ensuite essaye de supprimer à nouveau ce dossier eoRezo qui se situe en C:\PROGRAM FILES\
Si ça ne marche pas, supprime directement le dossier eoRezo en mode sans échec.
< http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >
PS: Ton OS installé est-il VISTA ?
Bonne chance
Al. -
Logfile of HijackThis v1.99.1
Scan saved at 09:33:58, on 04/04/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Running processes:
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\GRISOFT\AVG7\avgcc.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\GRISOFT\AVG7\avgw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\hijackthis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\Its Label\ItsTV\ItsTV.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
O4 - Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
est-ce que c'était ca qu'il fallait faire ? -
Adobe Reader 6.0 - Français
All To MP3 Converter 1.6
Anti-Hacker
Anti-Virus
ArcSoft ShowBiz 2
ATI Control Panel
ATI Display Driver
AVS Audio Tools version 4.1
Connexion Facile à Internet
Correctif pour DirectX - KB825116
Correctif Windows XP - KB821557
Correctif Windows XP - KB823559
Correctif Windows XP - KB824146
Correctif Windows XP (SP2) Q327979
Correctif Windows XP (SP2) Q328310
Correctif Windows XP (SP2) Q329112
Correctif Windows XP (SP2) Q329170
Correctif Windows XP (SP2) q329623
Correctif Windows XP (SP2) Q329909
Correctif Windows XP (SP2) Q331953
Correctif Windows XP (SP2) Q810565
Correctif Windows XP (SP2) Q810577
Correctif Windows XP (SP2) Q810833
Correctif Windows XP (SP2) Q811789
Correctif Windows XP (SP2) Q814033
Correctif Windows XP (SP2) Q814995
Correctif Windows XP (SP2) Q815485
Correctif Windows XP (SP2) Q817287
Correctif Windows XP (SP2) Q817606
HijackThis 1.99.1
HP Deskjet Preloaded Printer Drivers
HP Photo and Imaging 2.0 - Photosmart Cameras
HP PSC & OfficeJet 3.0
HP Software Update
Intel(R) Extreme Graphics Driver
Internet Explorer Q828750
InterVideo WinDVD Player
Java 2 Runtime Environment, SE v1.4.2
KBD
Macromedia Flash Player 8
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
NVIDIA GART Driver
Outlook Express Update Q330994
Package du correctif Windows XP [voir Q329115 pour plus de détails]
Package du correctif Windows XP [voir q329256 pour plus de détails]
Package du correctif Windows XP [voir Q329390 pour plus de détails]
Package du correctif Windows XP [voir Q329834 pour plus de détails]
Package du correctif Windows XP [voir Q331958 pour plus de détails]
PC CAMERA DATA SOURCE(6029)1.0(32-32)
Photo et imagerie HP 3.1
Photosmart 140,240,7200,7600,7700,7900 Series
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
RecordNow!
Sonic Update Manager
Sound Blaster Extigy
Thème Nature 2 Nature
Thème Québec
Trust 150 Spacecam Portable
Windows Live Messenger
Windows Live Sign-in Assistant -
Salut
Renseigne toi dans la section materiel, ils sont plus competent que moi dans ce domaine. Par contre, si tu n as pas de réponse, tu peux revenir sans problemes.
Ravi que tes soucis virus soit resolus. Essai de poster dans l autre partie du forum et si vraiment tu n'as pas de réponses, repostes sur ce topic avec plaisir.
Bonne soirée
-
bonsoir régis,
ok pour le pare feu tu as raison.autrement plus de problème mais je voulais savoir si je pouvais O/C mon proc et jusqu'où en fonction de mon matériel.J'ai lu un sujet sur le possésseur d'un amd xp 2200 poussé de 1800 mhz à 2200MHz avec la même carte mere que moi.J'arrive à le monter à1920 sans hausse de température importante mais je ne suis pas sur de mes réglages et je ne veux pas faire de bétise.Ce n'est pas pressé mais si je pouvais gagner un peu plus de puissance pourquoi pas.une derniere question concerne ma carte graphique, je ne joue pas trop et ma fille joue avec des jeux pas trop gourmand ,mais je me demande si je ne gagnerais pas en fluidité et rapidité en la changeant(sans mettre un prix fou)Voila comme tu le vois encore des questions
merci et A+ -
Salut Stéphane,
Kaspersky integre un pare feu?
A la place d ad watch qui surveille les modifications du registre, autant detenir un pare feu qui permettra a toi meme, de refuser et d accepter les processus a acceder au net.De la, le pare feu pourra bloques les intrusions.
Pour tes autres soucis, quels sont ils?
a+ -
salut régis,
juste un petit mot pour te dire que tout est en ordre sur mon pc,merci encore.Peux tu me conseiller un logiciel pour remplacer Ad-Watch et si c'est vraiment utile.Pour l'overclockink je dois me rendre sur quel forum
A+
stéphane -
Salut
ah voila , enfin....
Tu as cette version Ad-Aware SE Build 1.05 , desinstalles la !
Installes celle ci
Ad-Aware SE 1.06 <<nouvelle version.
http://www.lavasoftusa.com/software/adaware/
-Une aide:
http://www.tutopat.com/viewtopic.php?t=1191
- installe le patch français, tu pourras le trouver ici:
http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation).
http://pageperso.aol.fr/balltrap34/adawrevid.asf
a+ -
voila le rapport
Ad-Aware SE Build 1.05
Fichier journal créé le :dimanche 12 février 2006 19:09:39
Utilisation du fichier de définitions :SE1R91 08.02.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Références détectées lors de l’analyse :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(Index TAC :0):15 Nombre total de références
Tracking Cookie(Index TAC :3):1 Nombre total de références
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Définir : Rechercher les entrées à risque négligeable
Définir : Mode sécurisé (tjrs demander confirm.)
Définir : Analyser les processus actifs
Définir : Scan registry
Définir : Analyser en profondeur le registre
Définir : Analyser mes favoris IE pour rech. URL interdites
Définir : Analyser mon fichier Hosts
Extended Ad-Aware SE Settings
===========================
Définir : Décharger les modules et les processus reconnus pendant l’analyse
Définir : Ignorer les fichiers fractionnés lors de l’analyse des archives .CAB
Définir : Anal. reg. pr tous utili. et non pr utili. actuel uniqmnt
Définir : Toujours essayer de décharger les modules avant la suppression
Définir : Lors de la suppression, décharger l’Explorateur et IE si nécessaire
Définir : Perm. Win. supp. fich. en cours au proch. démar.
Définir : Supprimer les objets en quarantaine après la restauration
Définir : Forcer le blocage des fenêtres publicitaires
Définir : Sélec. auto. objets problématiques dans listes de résultats
Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
Définir : Inclure un récapitulatif des références dans le fichier journal
Définir : Inclure les détails des données ADS dans le fichier journal
Définir : Afficher l’écran d’accueil
Définir : Sauvegarder le fichier de définitions utilisé avant d’effectuer une mise à jour
Définir : Émettre un son à la fin de l’analyse en cas de détection d'objets critiques
12-02-2006 19:09:39 - L’analyse a démarré. (Analyse complète du système)
MRU List Objet reconnu !
Emplacement : : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Objet reconnu !
Emplacement : : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Objet reconnu !
Emplacement : : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Objet reconnu !
Emplacement : : .DEFAULT\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Objet reconnu !
Emplacement : : S-1-5-18\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Objet reconnu !
Emplacement : : S-1-5-20\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Objet reconnu !
Emplacement : : S-1-5-21-57989841-1935655697-839522115-500\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Objet reconnu !
Emplacement : : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Objet reconnu !
Emplacement : : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Affichage des processus en cours d'exécution
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 296
ThreadCreationTime : 12-02-2006 18:07:21
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 408
ThreadCreationTime : 12-02-2006 18:07:36
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 432
ThreadCreationTime : 12-02-2006 18:07:38
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 480
ThreadCreationTime : 12-02-2006 18:07:42
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Applications Services et Contrôleur
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 492
ThreadCreationTime : 12-02-2006 18:07:43
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 644
ThreadCreationTime : 12-02-2006 18:07:45
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 704
ThreadCreationTime : 12-02-2006 18:07:47
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 772
ThreadCreationTime : 12-02-2006 18:07:49
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [wrsssdk.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 808
ThreadCreationTime : 12-02-2006 18:07:49
BasePriority : Normal
FileVersion : 2,0,9,509
ProductVersion : 2, 0
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper SDK
LegalCopyright : Copyright (C) 2002 - 2005, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe
#:10 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 944
ThreadCreationTime : 12-02-2006 18:08:03
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorateur Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : EXPLORER.EXE
#:11 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Professional\
ProcessID : 1028
ThreadCreationTime : 12-02-2006 18:08:19
BasePriority : Normal
FileVersion : 6.2.0.208
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Résultat de l’analyse de la mémoire :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 15
Analyse du registre démarrée
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat de l’analyse du registre :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 15
Analyse approfondie du registre démarrée
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat de l’analyse approfondie du registre :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 15
Analyse des cookies de suivi lancée
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat de l’analyse des cookies de suivi :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 15
Analyse et examen approfondis des fichiers (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Objet reconnu !
Type : IECache Entry
Données : hansa@weborama[2].txt
Catégorie : Data Miner
Commentaire :
Valeur : C:\Documents and Settings\hansa\Cookies\hansa@weborama[2].txt
Résultat de l’analyse du disque pour C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 16
Analyse et examen approfondis des fichiers (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat de l’analyse du disque pour D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 16
Analyse du fichier Hosts…...
Emplacement du fichier Hosts :"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat d’analyse du fichier Hosts :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entrées analysées.
Nouv. obj. critiques :0
Objets détectés jusqu'à présent : 16
Analyses conditionnelles en cours...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Résultat d’analyse conditionnelle :
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nouv. obj. critiques : 0
Objets détectés jusqu'à présent : 16
19:24:09 Analyse terminée
Récap. de cette anal.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Durée tot. analyse :00:14:30.531
Objets analysés :121414
Objets identifiés :1
Objets ignorés :0
Nouv. obj. critiques :1 -
salut
passe en sans echec et lance ad aware, sauvegarde le rapport et donne le moi
a+ -
salut,
voilà le résultat:
Rapport fait à 18:37:04,29 le 12/02/2006
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
30/01/2006 13:33 <REP> Lavasoft
25/11/2005 12:11 62 desktop.ini
25/11/2005 12:11 <REP> ..
25/11/2005 12:11 <REP> Microsoft
25/11/2005 12:11 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 20849938432 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\Documents and Settings\All Users\Application Data
08/02/2006 13:11 <REP> SecTaskMan
25/01/2006 18:33 <REP> SSScanWizard
25/01/2006 18:33 <REP> SSScanAppDataDir
24/01/2006 08:49 <REP> Spybot - Search & Destroy
31/12/2005 11:57 <REP> InstallShield
31/12/2005 11:55 <REP> Sonic
31/12/2005 11:49 <REP> Roxio
17/12/2005 18:01 <REP> Trymedia
15/12/2005 09:36 <REP> Symantec
08/12/2005 17:23 <REP> Windows Genuine Advantage
04/12/2005 19:30 <REP> Zylom
31/10/2005 11:54 <REP> ScanSoft
19/10/2005 11:04 <REP> MSN6
18/10/2005 09:15 <REP> Kaspersky Anti-Virus Personal
17/10/2005 18:50 62 desktop.ini
17/10/2005 18:49 <REP> Microsoft
17/10/2005 18:49 <REP> .
17/10/2005 18:49 <REP> ..
1 fichier(s) 62 octets
17 R‚p(s) 20849934336 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\Documents and Settings\Default User\Application Data
17/10/2005 18:50 62 desktop.ini
17/10/2005 18:49 <REP> ..
17/10/2005 18:49 <REP> Microsoft
17/10/2005 18:49 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 20849934336 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\Documents and Settings\hansa\Application Data
04/02/2006 13:17 <REP> ScanSoft
04/02/2006 12:44 <REP> ArcSoft
02/02/2006 16:54 <REP> SuperAdBlocker.com
23/01/2006 10:10 <REP> OrphansRemover
11/01/2006 18:53 <REP> metafastfilm
11/01/2006 18:46 3601 bhrslog.txt
31/12/2005 12:03 <REP> Roxio
17/12/2005 13:26 <REP> Real
14/12/2005 19:57 <REP> OpenOffice.org2
04/12/2005 19:30 <REP> Zylom
15/11/2005 18:57 <REP> Webroot
12/11/2005 19:52 <REP> MSN6
09/11/2005 20:51 <REP> Canon
09/11/2005 20:46 <REP> XnView
08/11/2005 18:37 <REP> Lavasoft
05/11/2005 17:15 <REP> Sun
27/10/2005 14:14 <REP> Adobe
19/10/2005 17:29 <REP> Macromedia
19/10/2005 10:41 <REP> Free Download Manager
19/10/2005 10:22 <REP> Thunderbird
19/10/2005 10:10 <REP> Mozilla
19/10/2005 10:06 <REP> WinPatrol
17/10/2005 19:35 <REP> Identities
17/10/2005 19:35 62 desktop.ini
17/10/2005 19:35 <REP> ..
17/10/2005 19:35 <REP> .
17/10/2005 19:35 <REP> Microsoft
2 fichier(s) 3663 octets
25 R‚p(s) 20849934336 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\Documents and Settings\stephane\Application Data
03/02/2006 19:18 <REP> Webroot
02/02/2006 11:21 <REP> PopUpSentry.com
02/02/2006 10:13 <REP> SuperAdBlocker.com
25/01/2006 19:27 <REP> Canon
25/01/2006 18:33 <REP> ScanSoft
31/12/2005 12:00 <REP> Roxio
15/12/2005 09:36 <REP> IsolatedStorage
08/12/2005 16:40 <REP> Real
05/12/2005 12:25 <REP> OrphansRemover
20/11/2005 17:08 <REP> vlc
14/11/2005 12:55 <REP> Google
07/11/2005 16:36 <REP> Media Player Classic
04/11/2005 12:52 <REP> ArcSoft
31/10/2005 07:58 <REP> Help
26/10/2005 10:21 <REP> Azureus
22/10/2005 10:55 <REP> OpenOffice.org2
20/10/2005 09:56 <REP> Sun
19/10/2005 11:04 <REP> MSN6
19/10/2005 09:51 <REP> WinPatrol
19/10/2005 07:30 <REP> XnView
18/10/2005 12:26 <REP> Talkback
18/10/2005 12:26 <REP> Thunderbird
18/10/2005 12:15 <REP> Mozilla
18/10/2005 09:15 <REP> SpamTest
17/10/2005 19:07 <REP> Identities
17/10/2005 19:07 62 desktop.ini
17/10/2005 19:07 <REP> ..
17/10/2005 19:07 <REP> Microsoft
17/10/2005 19:07 <REP> .
17/10/2005 18:36 <REP> .ABC
17/10/2005 18:35 <REP> Lavasoft
17/10/2005 17:46 <REP> Macromedia
17/10/2005 17:21 <REP> Free Download Manager
17/10/2005 16:51 <REP> Adobe
17/10/2005 16:51 <REP> InterTrust
30/07/2005 06:22 12185 bhrslog.txt
2 fichier(s) 12247 octets
34 R‚p(s) 20849930240 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 20DC-C99D
R‚pertoire de C:\WINDOWS\Tasks
17/10/2005 19:02 6 SA.DAT
17/10/2005 19:01 65 desktop.ini
17/10/2005 19:01 <REP> ..
17/10/2005 19:01 <REP> .
2 fichier(s) 71 octets
2 R‚p(s) 20ÿ849ÿ930ÿ240 octets libres
******************************************
Recherche dans Program files
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
A+
- 1
- 2
- 3
- 4
- 5