Wlcom.exe besoin d'aide!

Bonjour,



depuis hier je suis aussi embeter par cette page qui s'ouvre régulièrement.
je vous poste le rapport "pre scan"
aider moi svp

http://pjjoint.malekal.com/files.php?id=20120203_g10w15n10w5u10

6 réponses

  1. manque un bout du rapport

    ^^

    supprime ca mannuellement je l ai mis dans le mauvais endroit pour sa suppression

    c:\Wlid.bat
    ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    _Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    1. re g3n.h@ckm@n, desole pour le retard , il fallait que je m'occupe des enfants apres l'ecole...
      voici le resultat:

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.028 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

      ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

      Mis à jour : 28/01/2012 | 00.45 Par g3n-h@ckm@n
      Utilisateur : SHAD (Administrateurs)
      Ordinateur : DESHA
      Système d'exploitation : Microsoft Windows XP (32 bits)
      Internet Explorer : 8.0.6001.18702
      Mozilla Firefox : 9.0.1 (fr)

      Switchs possibles :

      processes:: | file:: | folder:: | Registry::
      Driver:: | replace:: | DNS:: | Command::
      txt:: | Host:: | NsLook::
      list:: | IP:: | Kill:: | clean::
      Reboot:: | MBR:: | Fixmbr:: | 40:: | Zip::
      Tray::

      Script : 19:18:49

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

      Modification du registre effectuée

      ¤

      Supprimé : C:\Documents and Settings\All Users\Application Data\1FFDA4184F.sys

      ¤

      non Supprimé : C:\perlb
      1. desinstalle toutes tes version de java
        desinstalle adobe reader 9

        ====

        fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

        Lance Pre_script , une page vierge va s'ouvrir.

        selectionne tout le texte en gras ci-dessous, puis (clic droit/copier ou ctrl+c) :
        ___________________________________________________
        Kill::

        Registry::
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "QuickTime Task"=-
        "Adobe Reader Speed Launcher"=-
        "iTunesHelper"=-
        "WLID"=-
        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
        "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=-
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\OfferBox Browser]
        [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
        [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
        [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
        [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}]
        [-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EDFCB7CB-942C-4822-AF14-F0B687409848}]
        [-HKCU\Software\yhrmnrpm]
        [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "1900:UDP"=-
        "2869:TCP"=-
        [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
        "1900:UDP"=-
        "2869:TCP"=-

        file::
        C:\Documents and Settings\All Users\Application Data\1FFDA4184F.sys

        folder::
        C:\perlb
        c:\Wlid.bat
        C:\Documents and Settings\All Users\Application Data\espionServerData
        C:\Documents and Settings\All Users\Application Data\Htm Support Bait Deaf
        C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
        C:\Documents and Settings\All Users\Application Data\ukprfree
        C:\Program Files\Nlqzzmxvajj

        Mbr::

        clean::

        Reboot::

        ___________________________________________________

        colle-le ensuite (clic droit/coller ou ctrl+V) dans la page vierge.

        puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

        des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

        poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

        si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
        1. non mais desolé j ai beaucoup de boulot ^^ ca se passe au dessus