|
|
|
|
Bonjour, jai tjs le problème avec l'antivirus windows xp 2008 voici le rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:49:13, on 24/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\monjack.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_BE&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: WebManager Class - {D5792AA9-D373-4039-8670-2CDAB6A71F15} - C:\Program Files\BitDownload\TorrentManager.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB002" /M "Stylus DX3800"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: TomTom HOME.lnk = C:\Program Files\TomTom HOME\TomTomHOME.exe
O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
End of file - 14135 bytesConfiguration: Windows XP
Firefox 2.0.0.16
**DOUBLON**
|
Merci Marie =)
-----------\\ ToolBar S&D 1.1.1 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Sempron(tm) Processor 3400+ )
Phoenix - AwardBIOS v6.00PG
USER : erwin ( Administrator )
USER : Marie-Laure ( Administrator )
BOOT : Normal boot
"C:\ToolBar SD" ( MAJ : 20-08-2008|01:05 )
Option : [1] ( jeu. 21/08/2008|17:49 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(HP_Administrateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(HP_Administrateur) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(Marie-Laure) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://ie.redirect.hp.com/..."
"Default_Search_URL"="http://ie.redirect.hp.com/..."
"Search Bar"="http://www.google.com/ie"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://ie.redirect.hp.com/..."
"Default_Search_URL"="http://www.google.com/ie"
"Search Page"="http://ie.redirect.hp.com/..."
"Start Page"="http://ie.redirect.hp.com/..."
"Search Bar"="http://ie.redirect.hp.com/..."
--------------------\\ Recherche d'autres infections
C:\WINDOWS\System32\nvs2.inf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\fusioncache.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\GDIPFONTCACHEV1.DAT
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\IconCache.db
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\qawkugw.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\qawkugw_nav.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\qawkugw_navps.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\wsxhehdd.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Adobe\Acrobat\7.0\Cache\AcroFnt07.lst
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Adobe\Color\ACECache4.lst
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\iTunes\iPodDevices.xml
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\iTunes\iTunesPrefs.xml
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\QuickTime\QuickTime.qtp
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\SyncNotifier\SyncNotifier\Logs\080208_164652.log
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\SyncNotifier\SyncNotifier\Logs\081308_230817.log
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\SyncNotifier\SyncNotifier\Logs\081308_231835.log
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Apple Computer\SyncNotifier\SyncNotifier\Logs\082108_085626.log
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\csc.exe.3e4ac0af.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\ehExtHost.exe.fa7bea74.ini.inuse
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\ehshell.exe.a87fcbb.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\hpqthb08.exe.a935d1e0.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\HPZISMGR.EXE.2fd8c98f.ini.inuse
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\IEActivex.exe.cccdbce.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\Install.exe.446b110b.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\MCInstaller.exe.c95982a.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\ngen.exe.2c05686e.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\regasm.exe.11f1da13.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\RegAsm.exe.ca35bcc8.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\RegisterMCEApp.exe.19d07aaf.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\SetupMCL.exe.cacc9309.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\ApplicationHistory\SL56.tmp.bd2942a.ini
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\dbCache.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\dbCache.dat.index
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_773_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_bluedotmini_64_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_blue_star_l.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_capital32_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_darfur_image_icon_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_green_star_l.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_lil_earth_l.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_orangedotmini_64_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_picto_flag_l.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_purpledotmini_64_nh.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\icons\kh.google.com_icons_road_blue_l.png
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\images\khimg1.gif
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Google\GoogleEarth\images\khimg2.jpg
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\handle.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\oov1_skindefV3.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\administrativeInfo.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\albumImagesTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\albumImagesTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\albumTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\albumTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\CB_Server_Errors.txt
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\EXIFTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\EXIFTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\imageTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\imageTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\imageTable.fpt
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\keywordImagesTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\keywordImagesTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\keywordTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\keywordTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\managedFolderTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\pathnameTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\pathnameTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\propertiesTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\propertiesTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\ROFImagesTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\ROFImagesTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\ROFTable.cdx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\HP\Digital Imaging\db\ROFTable.dbf
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Identities\{60B3BF1F-884A-4351-836D-BA4E86156C55}\Microsoft\Outlook Express\BoŒte d'envoi.dbx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Identities\{60B3BF1F-884A-4351-836D-BA4E86156C55}\Microsoft\Outlook Express\BoŒte de r‚ception.dbx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Identities\{60B3BF1F-884A-4351-836D-BA4E86156C55}\Microsoft\Outlook Express\Folders.dbx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Identities\{60B3BF1F-884A-4351-836D-BA4E86156C55}\Microsoft\Outlook Express\Offline.dbx
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Wallpaper1.bmp
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Credentials\S-1-5-21-1532203870-2756969240-765022916-1007\Credentials
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\ehome\Video.db
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\HelpCtr\HelpSessionHistory.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Internet Explorer\MSIMGSIZ.DAT
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\CurrentDatabase_219.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\CurrentDatabase_360.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\CurrentDatabase_59R.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _0.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _1.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _2.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _3.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _4.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\E- _5.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _0.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _1.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _2.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _3.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _4.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\F- _5.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\lastplayed.wpl
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\LocalMLS_0.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\LocalMLS_1.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\LocalMLS_2.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\LocalMLS_3.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\wmdbexport.xml
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\wmpfolders.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_0.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_1.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_2.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_3.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_4.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{4BC45A78-0362-4CCA-A2DE-4F7EF67EFF15}_5.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_0.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_1.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_2.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_3.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_4.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\{8F41D133-45B0-4597-BF88-27B078AADA25}_5.wmdb
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\Cache d'images\LocalMLS\{27A2250C-DED5-4091-8CFF-0FFE3280D204}.jpg
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Media Player\Cache d'images\LocalMLS\{FF6D7684-4C3B-4AF1-A30C-9ACB58033606}.jpg
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Messenger\activesharingfolder.dat
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Messenger\cold_hot_1@hotmail.com\ObjectStore\objectstore.v2
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Messenger\cold_hot_1@hotmail.com\ObjectStore\Backgrounds\H0C+m00zJnUEpqvrpUwmEeNk+m4=.dt2
C:\DOCUME~1\HP_ADM~1\LOCALS~1\APPLIC~1\Microsoft\Messenger\cold_hot_1@hotmail.com\ObjectStore\Backgrounds\H0C+m00zJnUEpqvrpUwmEeNk+m4=.id2
ect ...
**************************************** fais ce qui suit : Télécharges Navilog1 sur ton bureau : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe !! Déconnectes toi,désactives tes défences( anti-virus,anti-spyware ) et fermes bien toutes tes applications le temps de la manipe !! Ensuite double clique sur navilog1.exe pour lancer l'installation. Une fois l'installation terminée, le fix s'exécutera automatiquement. (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau). Laisses-toi guider. Au menu principal, choisis 1 et valides. (ne fais pas le choix 2,3 ou 4 sans notre avis/accord) Patiente jusqu'au message : *** Analyse Termine le ..... *** Appuies sur une touche comme demandé, le bloc-note va s'ouvrir. Copie-colle l'intégralité de son contenu dans ta prochaine réponse et attends la suite . (Le rapport est en outre sauvegardé à la racine du disque "C\:fixnavi.txt" ) TUTO (aide) : http://www.malekal.com/Adware.Magic_Control.php#mozTocId595901 Rien ne sert de courir .... Non, ça sert à rien ... ---sKe--- "Baby, I'm going on an airplane, And I don't know if I'll be back again." IMPORTANT : ne vous croyez pas tiré d'affaire tant qu'on ne vous l'a pas dit !
|
Salut,
|
Bien ... On continue :
|
Salut,
|
Bien ...
|
Possible ...
|
Voila, il ny avt pas de rapport de malware bytes sinon voici le rapport de genproc
|
Bon ... on va voir ...
|
Voila voici le rapport
|
Suite de la manipe ( nettoyage ), fais exactement ce qui suit :
|
Salut,
|
Salut,
|
Salut,
|
Salut,
|
Très bien ... encore une ou deux vérifications et on finalise ...
|
Il y a un petit prob avec le site que tu mas dit (virustotal) je ne sais pas coller ce que tu mas dit et dès que je cloque a l'endroit ou coller j'ai une fenêtre qui souvre pour que je sélectionne un fichier de lordi alors la je tape K:/autorun.exeet il me dit quil ne peut pas le lire et que je dois vérifiez qu'il y a un disque présent... |
C'est que tu n'as pas brancher l'unité externe sur le bon port .... Sinon passe aux autres fichiers ....
Rien ne sert de courir .... Non, ça sert à rien ... ---sKe---
|