Avira antivir se referme automatiquement

sirpapy

Habitué
Bonjour,

Je viens d'installer l'antivirus Avira Antivir. Mais aprés l'installation dés que je l'ouvre il se referme automatiquement sans méssage d'erreur. Aidez moi SVP
Je suis sous XP professional
Merci d'avance
 

jacktara

Modérateur
Staff
Désinstalle et réinstalle pour être sûr que c'est pas un problème d'installation ;)
Tu viens de l'installer ou c'est apparus après utilisation ?
 

Ataw

Nouveau membre
je n'ai pas vraiment d'idée mais as-tu essayé de redémarrer ton PC?

Si ca ne résout pas le problème je ne peux malheureusement pas t'aider et il faudra attendre l'avis de personnes plus expérimentées.
 

sirpapy

Habitué

Je viens de l'installer et depuis ça fait comme ça
 

sirpapy

Habitué


J'ai essayer de redémarrer mais ça marche toujours pas
 

jacktara

Modérateur
Staff
Ben j'te propose alors une ré-installation du soft histoire de voir ce que ça donne ;)

Sinon c'est quel version ?
Téléchargé où ?
Un autre antivirus d'installé sur l'ordi ?
Définis comme antivirus par défaut ?
 

sirpapy

Habitué


Je l'ai fait ça marche toujours pas. Je l'ai télécharger sur la page officiel de l'antivirus, c'est la derniere version. Et non a part celui là j'ai pas d'autres antivirus
 

thor37230

Grand Maître
essaies un autre anti-virus pour voir, désinstalle complétement Antivir et installe MSE
 

papiline

Habitué


Merci, je l'installe pour voir
 

papiline

Habitué
je l'ai installer puis j'ai analysé l'ordinateur, mais ç'est entrain de supprimer des fichers clés de windows(google chrome marche plus ainsi que ms office etc...)
 

papiline

Habitué


Voila le rapport de HijackThis v2.0.4

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:08:42, on 26/08/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe
C:\Program Files\BitTorrent Ultra Accelerator\BitTorrent Ultra Accelerator.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\wintqeg.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Family\Mes documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sn/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: BittorrentBar_FR Toolbar - {ef79f67a-6ad7-4715-a0f8-932fca442023} - C:\Program Files\BittorrentBar_FR\prxtbBitt.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PCTBHO - {293A63F7-C3B6-423a-9845-901AC0A7EE6E} - C:\Program Files\Agence-Exclusive\pctutoBHO.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: BittorrentBar_FR - {ef79f67a-6ad7-4715-a0f8-932fca442023} - C:\Program Files\BittorrentBar_FR\prxtbBitt.dll
O3 - Toolbar: BittorrentBar_FR Toolbar - {ef79f67a-6ad7-4715-a0f8-932fca442023} - C:\Program Files\BittorrentBar_FR\prxtbBitt.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [pctuto] "C:\Program Files\Agence-Exclusive\pctuto.exe"
O4 - HKLM\..\Run: [autoupdater] C:\Documents and Settings\Family\Application Data\Agence-Exclusive\Agence-Exclusive\autoupdater.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [SpeedConnectStartUp] C:\Program Files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe -run
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: BitTorrent Ultra Accelerator.lnk = C:\Program Files\BitTorrent Ultra Accelerator\BitTorrent Ultra Accelerator.exe
O4 - Startup: Dos Optimizer.pif = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe

--
End of file - 9711 bytes
 

thor37230

Grand Maître
désinstalle les softs à la con : BitComet, SpeedConnect Internet Accelerator


Nettoyage avec

Ensuite :

(la réactiver une fois les menaces supprimés)

scan ton pc avec en mettant à jour au préalable (scan complet pour Malwarebytes)

♦ Télécharge

♦ Déconnecte toi et ferme toutes applications en cours(désactive momentanément ton antivirus/pare-feu)

♦ Double clique(clic droit "executer en temps qu'administrateur pour vista) sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

♦ Double-clique(clic droit "executer en temps qu'administrateur pour vista) sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

♦ Au menu principal choisis l'option "Scanner".

♦ Laisse travailler l'outil et ne touche à rien ...

♦ Poste le rapport qui apparait à la fin , sur le forum ...

( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

♦ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.




 

papiline

Habitué


Merci pour votre réponse voila le log


======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par TeamXscript le 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web:

C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 15:08:26 le 30/08/2011, Mode normal

Microsoft Windows XP Professionnel Service Pack 3 (X86)
Family@MAMINA ( )

============== RECHERCHE ==============


Fichier trouvé: C:\WINDOWS\system32\ConduitEngine.tmp
Dossier trouvé: C:\Documents and Settings\Family\Application Data\Agence-Exclusive
Dossier trouvé: C:\Documents and Settings\Family\Local Settings\Application Data\Agence-Exclusive
Dossier trouvé: C:\Documents and Settings\Family\Local Settings\Application Data\Conduit
Dossier trouvé: C:\Program Files\Conduit
Dossier trouvé: C:\Documents and Settings\Family\Local Settings\Application Data\ConduitEngine
Dossier trouvé: C:\Program Files\ConduitEngine
Dossier trouvé: C:\Documents and Settings\Family\Application Data\PriceGong
Dossier trouvé: C:\Documents and Settings\Family\Application Data\ShoppingReport2
Dossier trouvé: C:\Program Files\ShoppingReport2

Clé trouvée: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Clé trouvée: HKLM\Software\Classes\CLSID\{AC6240AE-33B6-40D3-8683-31BBE86049A0}
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6240AE-33B6-40D3-8683-31BBE86049A0}
Clé trouvée: HKLM\Software\Classes\Interface\{A1F1ECD3-4806-44C6-A869-F0DADF11C57C}
Clé trouvée: HKLM\Software\Classes\TypeLib\{0BF73E27-2734-4F7B-925A-4BBB1457F5FA}
Clé trouvée: HKLM\Software\Classes\Conduit.Engine
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.HbAx
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.HbAx.1
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.HbInfoBand
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.HbInfoBand.1
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.IEButton
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.IEButton.1
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.IEButtonA
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.IEButtonA.1
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.RprtCtrl
Clé trouvée: HKLM\Software\Classes\ShoppingReport2.RprtCtrl.1
Clé trouvée: HKLM\Software\Classes\Toolbar.CT2849852
Clé trouvée: HKLM\Software\Conduit
Clé trouvée: HKLM\Software\conduitEngine
Clé trouvée: HKLM\Software\ShoppingReport2
Clé trouvée: HKCU\Software\Conduit
Clé trouvée: HKCU\Software\conduitEngine
Clé trouvée: HKCU\Software\PriceGong
Clé trouvée: HKCU\Software\ShoppingReport2
Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A472B3FF-C736-4334-AC28-2919B239E1A9}
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShoppingReport2

Valeur trouvée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D}


============== SCAN ADDITIONNEL ==============

**** Google Chrome Version [13.0.782.215] ****

Extension\elhjaoldnkkbifioodjndkijecdeinld (C:\DOCUME~1\Family\LOCALS~1\Temp\crx8B.tmp) (x)

-- C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default --
Preferences - default_search_provider: "Google" (Activé: true) (?)
Preferences - homepage: hxxp://www.google.com
Preferences - homepage_is_newtabpage: false
Plugin - Chrome NaCl (Activé: false) (C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\13.0.782.215\ppGoogleNaClPluginChrome.dll)
Plugin - "Chrome NaCl" (Activé: false)

========================================

**** Internet Explorer Version [8.0.6001.18702] ****

HKCU_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKCU_Main|Start Page - hxxp://www.google.sn/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Start Page - hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKCU_URLSearchHooks|{ef79f67a-6ad7-4715-a0f8-932fca442023} - "BittorrentBar_FR Toolbar" (C:\Program Files\BittorrentBar_FR\prxtbBitt.dll)
HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "BittorrentBar_FR Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...)
HKCU_Toolbar\WebBrowser|{EF79F67A-6AD7-4715-A0F8-932FCA442023} (C:\Program Files\BittorrentBar_FR\prxtbBitt.dll)
HKLM_Toolbar|{ef79f67a-6ad7-4715-a0f8-932fca442023} (C:\Program Files\BittorrentBar_FR\prxtbBitt.dll)
HKLM_Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D} (C:\Program Files\ConduitEngine\prxConduitEngine.dll)
HKCU_ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A} - C:\Program Files\Internet Download Manager\IEMonitor.exe (x)
HKCU_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Program Files\Internet Download Manager\IDMan.exe (x)
HKLM_ElevationPolicy\{A472B3FF-C736-4334-AC28-2919B239E1A9} - C:\Program Files\ConduitEngine\ConduitEngineHelper.exe (?)
HKLM_ElevationPolicy\{D4F64D18-D596-4D33-8A7C-00FBBFE9C5B9} - C:\Documents and Settings\Family\Local Settings\Application Data\Conduit\CT2849852\BittorrentBar_FRAutoUpdateHelper.exe (?)
HKLM_ElevationPolicy\{DA4CBC01-F732-4DF7-91FF-B9B7A873CFFE} - C:\Program Files\BittorrentBar_FR\BittorrentBar_FRToolbarHelper.exe (?)
HKLM_ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} - C:\Program Files\Internet Download Manager\IDMan.exe (x)
HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
BHO\{30F9B915-B755-4826-820B-08FBA6BD249D} - "Conduit Engine " (C:\Program Files\ConduitEngine\prxConduitEngine.dll)
BHO\{ef79f67a-6ad7-4715-a0f8-932fca442023} - "BittorrentBar_FR Toolbar" (C:\Program Files\BittorrentBar_FR\prxtbBitt.dll)

========================================

C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 0 Fichier(s)

C:\Ad-Report-SCAN[1].txt - 30/08/2011 15:09:03 (1151 Octet(s))

Fin à: 15:09:26, 30/08/2011

============== E.O.F ==============
 

thor37230

Grand Maître
Ok, Relance Ad-Remover et choisis l'option Nettoyer.

es ce que Malwarebytes a trouvé des indésirables?
 

papiline

Habitué
oui 81 attendez je vous poste le log de malaware

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Version de la base de données: 7610

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

30/08/2011 15:04:08
mbam-log-2011-08-30 (15-04-08).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 181762
Temps écoulé: 1 heure(s), 11 minute(s), 6 seconde(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 74

Processus mémoire infecté(s):
c:\documents and settings\Family\application data\agence-exclusive\agence-exclusive\autoupdater.exe (PUP.Tuto4PC) -> 2028 -> Unloaded process successfully.

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB38E21A-0133-419D-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoupdater (PUP.Tuto4PC) -> Value: autoupdater -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\Family\application data\agence-exclusive\agence-exclusive\autoupdater.exe (PUP.Tuto4PC) -> Quarantined and deleted successfully.
c:\zpharaoh.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\BADARA\aep - dialiguel\dossier pdf dialiguel\dossier pdf dialiguel .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\BADARA\assainissement sicap mbao 2009\brouillon\dossier sicap mbao\rapport technique du projet_ep_sicap mba0.doc .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\BADARA\rapports socio-économique pepam-ba final\rapport socioeconomique du site keur samba ka.doc .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\BADARA\rapports socio-économique pepam-ba final\rapport socioeconomique du site ndemene tata (1).doc .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\BADARA\rapports socio-économique pepam-ba final\rapport socioeconomique du site ndramé ibra - copie.doc .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\graphics .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\lang .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\ar-SA\ar-SA .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\cs-CZ\cs-CZ .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\da-DK\da-DK .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\de-DE\de-DE .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\el-GR\el-GR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\en-US\en-US .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\es-ES\es-ES .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\fr-FR\fr-FR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\hu-HU\hu-HU .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\it-IT\it-IT .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\ja-JP\ja-JP .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\ko-KR\ko-KR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\nb-NO\nb-NO .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\pl-PL\pl-PL .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\pt-BR\pt-BR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\pt-PT\pt-PT .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\ru-RU\ru-RU .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\sl-SI\sl-SI .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\sv-SE\sv-SE .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Graphics\lang\th-TH\th-TH .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\IIPS\iips .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\IIPS\x32\x32 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\IIPS\x64\x64 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\lang .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\ar-SA\ar-SA .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\cs-CZ\cs-CZ .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\de-DE\de-DE .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\es-ES\es-ES .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\fi-FI\fi-FI .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\hu-HU\hu-HU .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\it-IT\it-IT .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\ko-KR\ko-KR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\nl-NL\nl-NL .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\pt-BR\pt-BR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\pt-PT\pt-PT .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\ru-RU\ru-RU .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\sk-SK\sk-SK .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\sl-SI\sl-SI .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\sv-SE\sv-SE .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\th-TH\th-TH .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\tr-TR\tr-TR .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\drivers\Lang\zh-CN\zh-CN .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\mamina 10\num 2010\num 2010 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\mamina 10\num 2010\fa\sama religion\video_ts fass touré 2010\video_ts fass touré 2010 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\mamina 10\num 2010\num1\num1 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\mamina 10\num 2010\num3\num3 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\RECYCLER\s-1-5-21-1123561945-1035525444-1801674531-1004\s-1-5-21-1123561945-1035525444-1801674531-1004 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\situation juridique_tr.doc .exe (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
c:\discmamina\situation sénégal.doc .exe (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
c:\discmamina\ta photo de 18 mois.doc .exe (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
c:\discmamina\6300\Photos\Photos .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\family\coran\coran .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\ft plus\waximag.doc .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\num\photos1\nouv née ab&ib\nouv née ab&ib .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\num\photos1\nouv née ab&ib\100_FUJI\100_fuji .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\photos\photos adndiaye\photos famille\photos famille .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\photos\photos adndiaye\photos famille\photos\photos .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\photos\photos adndiaye\photos famille\photos\photos adndiaye\photos adndiaye .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\photos\photos adndiaye\photos famille\photos\photos adndiaye\photos adndiaye\photos adndiaye .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\photos\photos adndiaye\photos famille\photos\photos adndiaye\photos adndiaye\ibou sakho\ibou sakho .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\saat a a t ft\CD 2\CD 2 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\discmamina\saat a a t ft\cd1\cd1 .exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\documents and settings\Family\mes documents\downloads\pctuto_01net_emule.exe (Trojan.Eorezo) -> Quarantined and deleted successfully.
c:\documents and settings\Family\mes documents\downloads\xvidsetup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
d:\zpharaoh.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
 
Vous devez vous inscrire ou vous connecter pour répondre ici.
Derniers messages publiés
Statistiques globales
Discussions
730 122
Messages
6 717 682
Membres
1 586 355
Dernier membre
Chris7miles77
Partager cette page
Haut