LE NEWSMAGAZINE Nº1 DES NOUVELLES TECHNOLOGIES
172 utilisateurs connectés

Elitum.EliteBar

lionx le 14 septembre 2005 à 13h20
comment enleve t on ce Elitum.EliteBar
j'essaiyais spybot,adaware,ravantivirus n'a rien donné
je colle ici rapport hijack,aidez moi

Logfile of HijackThis v1.99.1
Scan saved at 13:19:39, on 14/09/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
J:\WINNT\System32\smss.exe
J:\WINNT\system32\csrss.exe
J:\WINNT\system32\winlogon.exe
J:\WINNT\system32\services.exe
J:\WINNT\system32\lsass.exe
J:\WINNT\system32\svchost.exe
J:\WINNT\system32\LEXBCES.EXE
J:\WINNT\system32\spoolsv.exe
J:\WINNT\system32\LEXPPS.EXE
J:\WINNT\system32\svchost.exe
J:\Program Files\ewido\security suite\ewidoctrl.exe
J:\Program Files\Ahead\InCD\InCDsrv.exe
J:\WINNT\system32\nvsvc32.exe
E:\Program Files\GeCAD\RAV8 Desktop\ravmon.exe
J:\WINNT\system32\regsvc.exe
J:\WINNT\system32\MSTask.exe
J:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
J:\WINNT\system32\stisvc.exe
J:\WINNT\System32\WBEM\WinMgmt.exe
J:\WINNT\system32\svchost.exe
J:\WINNT\system32\svchost.exe
J:\WINNT\Explorer.EXE
J:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
J:\Program Files\Logitech\Video\LogiTray.exe
J:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
J:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
J:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
J:\Program Files\Ahead\InCD\InCD.exe
E:\Program Files\GeCAD\RAV8 Desktop\ravtray8.exe
J:\Program Files\PopUp Killer\popupkiller.EXE
J:\Program Files\Yahoo!\Messenger\ypager.exe
E:\Program Files\Spyware Doctor\swdoctor.exe
J:\Program Files\MSN Messenger\MsnMsgr.Exe
J:\WINNT\system32\LVComS.exe
J:\WINNT\system32\wuauclt.exe
F:\Program Files\eDonkey2000y\edonkey2000.exe
J:\Program Files\Internet Explorer\IEXPLORE.EXE
M:\Program Files\ABC1\abc.exe
J:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
J:\progdvb marche\ProgDVB\ProgDVB.exe
J:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search123forme.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.search123forme.com/sp2.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/e(...)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.search123forme.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "J:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechVideoRepair] J:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] J:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "J:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "J:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [InCD] J:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] J:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RAV8Tray] E:\Program Files\GeCAD\RAV8 Desktop\ravtray8.exe
O4 - HKLM\..\Run: [PopUpKiller] J:\Program Files\PopUp Killer\popupkiller.EXE
O4 - HKLM\..\Run: [NeroCheck] J:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Yahoo! Pager] J:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Spyware Doctor] "E:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MsnMsgr] "J:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = J:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = J:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ravmon.exe.lnk = E:\Program Files\GeCAD\RAV8 Desktop\ravmon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - J:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mytotalsearch.com/menusearch.html?p=CPXXXXXX59
O8 - Extra context menu item: &Yahoo! Search - file:///J:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Pages liées - res://J:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://J:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///J:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///J:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///J:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - J:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - J:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_s(...)
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B7DE783-E4FA-414A-8E67-F9C7C4DF0E17}: NameServer = 80.10.246.130 80.10.246.3
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - J:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - J:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - J:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - J:\WINNT\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINNT\system32\nvsvc32.exe
O23 - Service: RAV8 File Monitor (ravmon8) - GeCAD srl - E:\Program Files\GeCAD\RAV8 Desktop\ravmon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - J:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

-------
dominique


À PROPOS DU FORUM MICRO HEBDO

LES FORUMS THÉMATIQUES ET TECHNIQUES

LES FORUMS GÉNÉRAUX

ARCHIVES DU FORUM

publicité
01Informatique
01 INFORMATIQUE
L'hebdo de référence des décideurs informatiques.
Micro Hebdo
MICRO HEBDO
L'hebdo qui vous simplifie la micro
et Internet.
L'Ordinateur Individuel
L'ORDINATEUR INDIVIDUEL
Le mensuel informatique qui vous informe et vous conseille.
Nous contacter  |  Charte de confiance  |  Voir notice légale

01net.  -  01men  -  RMC  -  BFM Radio  -  BFM TV  -  TousLesPodcasts  -  01informatique.fr  -  Association RMC-BFM
Tous droits réservés © 1999 - 2009 Internext - 01net.