PAGE PUB
Résolu
turquoise38
Messages postés
109
Date d'inscription
Statut
Membre
Dernière intervention
-
Utilisateur anonyme - 17 janv. 2009 à 19:38
Utilisateur anonyme - 17 janv. 2009 à 19:38
A voir également:
- PAGE PUB
- Supprimer pub youtube - Accueil - Streaming
- Supprimer une page word - Guide
- Stop pub gratuit - Télécharger - Divers Utilitaires
- Netflix avec pub avis - Accueil - Streaming
- Imprimer tableau excel sur une page - Guide
29 réponses
pourquoi depuis une semaine je me balade avec vous pour "réparer" mon PC pour 1 truc simple?
si c'est si simple pourquoi tu te désinfectes pas toute seule?
si c'est si simple pourquoi tu te désinfectes pas toute seule?
turquoise38
Messages postés
109
Date d'inscription
Statut
Membre
Dernière intervention
je ne suis pas sure que votre réponse soit bien adaptée!
Salut,
https://forums.commentcamarche.net/forum/s/u/turquoise38
Tu comptes en faire combien des topics ?
"Mon Cher V-X, explique-moi brièvement pourquoi depuis une semaine je me balade avec vous pour "réparer" mon PC pour 1 truc simple?"
---> Si tu n'est pas satisfait, va chez un informaticien qui te réglera le problème mais faudra sortir le portefeuille ;)
https://forums.commentcamarche.net/forum/s/u/turquoise38
Tu comptes en faire combien des topics ?
"Mon Cher V-X, explique-moi brièvement pourquoi depuis une semaine je me balade avec vous pour "réparer" mon PC pour 1 truc simple?"
---> Si tu n'est pas satisfait, va chez un informaticien qui te réglera le problème mais faudra sortir le portefeuille ;)
????????????
bonsoir Mr jfkpresident,je comprends que ns puissions avoir ts un métier et vie de famille! j'en afis partie!
Ceci dit, depuis plus d'une semaine ,je sollicie votre site pour 1 pblème, me semble-t-il, banal:
"des pages pubs qui s'affichent sauvagement".
Aussi je sollicite l'aide de votre site, et qq'1 de virtuel,V-X , accepte de m'aider. De protocole en protocole, j'essaie de suivre ses instructions...5 jours après les protocoles se poursuivent...puis des échanges inadéquats et pas sympas s'affichent entre d'autres personnes virtuelles de ce site!! A n'y rien comprendre!
Ce V-X qui m'a si bien aidé, disparait, suite à un échange affiché avec qq'1 d'autre!!
D'autres pesonnes se relaient pour me proposer des aides, me demandent de leur renvoyer des rapports suite à des installations qu'ils me suggèrent. Et puis pas de réponse...
J'avoue, au bout d'une semaine être désarconnée quant à l'aide fournie...Votre site a récolté bcp d'informations envoyées dans mes rapports.Qu'allez-vous en faire??
Je vais faire copie de ce problème avec votre site, à moins que vs essayez de me renseigner+ ce qui se passe! En attendant, que fais-je de ts ces logiciels installés et de ces rapports??
Ceci dit, depuis plus d'une semaine ,je sollicie votre site pour 1 pblème, me semble-t-il, banal:
"des pages pubs qui s'affichent sauvagement".
Aussi je sollicite l'aide de votre site, et qq'1 de virtuel,V-X , accepte de m'aider. De protocole en protocole, j'essaie de suivre ses instructions...5 jours après les protocoles se poursuivent...puis des échanges inadéquats et pas sympas s'affichent entre d'autres personnes virtuelles de ce site!! A n'y rien comprendre!
Ce V-X qui m'a si bien aidé, disparait, suite à un échange affiché avec qq'1 d'autre!!
D'autres pesonnes se relaient pour me proposer des aides, me demandent de leur renvoyer des rapports suite à des installations qu'ils me suggèrent. Et puis pas de réponse...
J'avoue, au bout d'une semaine être désarconnée quant à l'aide fournie...Votre site a récolté bcp d'informations envoyées dans mes rapports.Qu'allez-vous en faire??
Je vais faire copie de ce problème avec votre site, à moins que vs essayez de me renseigner+ ce qui se passe! En attendant, que fais-je de ts ces logiciels installés et de ces rapports??
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
C'est plus clair comme cela .
Pourquoi tu ne continu pas avec V-X ?
Peux tu me donner le lien initial du topique ou tu as posté la premiere fois ?
Rien et il ne sont pas exploitables a des fins malhonnetes ,mais il peuvent etre vus de tous ce qui est la démarche de CCM .
Pourquoi tu ne continu pas avec V-X ?
Peux tu me donner le lien initial du topique ou tu as posté la premiere fois ?
Votre site a récolté bcp d'informations envoyées dans mes rapports.Qu'allez-vous en faire??
Rien et il ne sont pas exploitables a des fins malhonnetes ,mais il peuvent etre vus de tous ce qui est la démarche de CCM .
salut turquoise ,
Les sujets ont était supprimer par les modérateur de CCM.
Chimay8 t'avais reprise en main.
Donc comme je t'avais commencer je vais finir mais prévient chimay8 que je t'ai reprise en main.
merci.
▶ Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
/!\ Déconnectes toi et fermes toutes applications en cours/!\
● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
● Double clique sur l'icône Ad-removersituée sur ton bureau
● Au menu principal choisi l'option "A"
● Postes le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Les sujets ont était supprimer par les modérateur de CCM.
Chimay8 t'avais reprise en main.
Donc comme je t'avais commencer je vais finir mais prévient chimay8 que je t'ai reprise en main.
merci.
▶ Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
/!\ Déconnectes toi et fermes toutes applications en cours/!\
● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
● Double clique sur l'icône Ad-removersituée sur ton bureau
● Au menu principal choisi l'option "A"
● Postes le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
coucou V-X, te revoilà! super! Voici le rapport:
------- Logfile of AD-Remover 1.0.8.9 by C_XX | ONLY XP/VISTA -------
# START AT: 8:29:22 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 37
+--------------------| Boonty/Boonty Games Elements found :
.
.
+--------------------| Eorezo Elements found :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Documents and Settings\berlandis\Application Data\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\berlandis\Application Data\EoRezo\host.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\user.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db\cat.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\userConfig.xml
+--------------------| Everest Casino/Everest Poker Elements found :
.
.
------- Logfile of AD-Remover 1.0.8.9 by C_XX | ONLY XP/VISTA -------
# START AT: 8:29:22 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 37
+--------------------| Boonty/Boonty Games Elements found :
.
.
+--------------------| Eorezo Elements found :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Documents and Settings\berlandis\Application Data\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\berlandis\Application Data\EoRezo\host.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\user.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db\cat.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\userConfig.xml
+--------------------| Everest Casino/Everest Poker Elements found :
.
.
DESOLEE, le voilà
------- Logfile of AD-Remover 1.0.8.9 by C_XX | ONLY XP/VISTA -------
# START AT: 8:29:22 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 37
+--------------------| Boonty/Boonty Games Elements found :
.
.
+--------------------| Eorezo Elements found :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Documents and Settings\berlandis\Application Data\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\berlandis\Application Data\EoRezo\host.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\user.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db\cat.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\userConfig.xml
+--------------------| Everest Casino/Everest Poker Elements found :
.
.
+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
HKCU\Software\FunWebProducts
.
+--------------------| It's TV Elements found :
HKCU\SOFTWARE\ItsLabel
.
C:\Documents and Settings\berlandis\Application Data\ItsLabel
C:\Documents and Settings\berlandis\Application Data\ItsLabel\ItsTV
C:\Documents and Settings\berlandis\Application Data\ItsLabel\ItsTV\itsTV.xml
+--------------------| Sweetim Elements found :
.
HKCU\SOFTWARE\SWEETIE
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKLM\SOFTWARE\Macrogaming
HKLM\~\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\~\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\Program Files\Macrogaming
C:\Program Files\Macrogaming\SweetIM
C:\Program Files\Macrogaming\SweetIM\conf
C:\Program Files\Macrogaming\SweetIM\data
C:\Program Files\Macrogaming\SweetIM\conf\users
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr
C:\Program Files\Macrogaming\SweetIM\conf\users\main_user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\lastuse_SpecialFX.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr\user_config.xml
C:\Program Files\Macrogaming\SweetIM\data\contentdb
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010859.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020158.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050001.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050002.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\cache_indx.dat
+--------------------| ADDED SCAN :
+---------- Scanning prefs.js ... ( # Mozilla User Preferences )
..\r43dkw3q.default\prefs.js :
~~~~ Mozilla FireFox version [Unable to get version] ~~~~
* Browser Search Default Engine: "Yahoo"
* Browser Search Selected Engine: "Yahoo"
* Browser Search Default Url: "https://www.google.com/webhp?lr=&ie=UTF-8&oe=UTF-8&gws_rd=ssl"
* Browser Startup HomePage: "http://eo.st"
.
FOUND - user_pref("browser.startup.homepage", "http://eo.st");
+---------------------------------------------------------------------------+
~~~~ Internet Explorer version 7.0.5730.11 ~~~~
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://www.google.fr/
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
+---------------------------------------------------------------------------+
[~5369 bytes] - "C:\AD-report-Scan-07.01.2009.log"
[~5153 bytes] - "C:\AD-report-Scan-14.01.2009.log"
# END at: 8:30:20 | 14/01/2009 - Time elapsed: 58.4 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 96 lines ]
+---------------------------------------------------------------------------+
------- Logfile of AD-Remover 1.0.8.9 by C_XX | ONLY XP/VISTA -------
# START AT: 8:29:22 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 37
+--------------------| Boonty/Boonty Games Elements found :
.
.
+--------------------| Eorezo Elements found :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Documents and Settings\berlandis\Application Data\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo\cmhost.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\ConfMedia.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop
C:\Documents and Settings\berlandis\Application Data\EoRezo\host.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\user.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\db\cat.cyp
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\config.xml
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\berlandis\Application Data\EoRezo\eoDesktop\userConfig.xml
+--------------------| Everest Casino/Everest Poker Elements found :
.
.
+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :
.
HKCU\Software\FunWebProducts
.
+--------------------| It's TV Elements found :
HKCU\SOFTWARE\ItsLabel
.
C:\Documents and Settings\berlandis\Application Data\ItsLabel
C:\Documents and Settings\berlandis\Application Data\ItsLabel\ItsTV
C:\Documents and Settings\berlandis\Application Data\ItsLabel\ItsTV\itsTV.xml
+--------------------| Sweetim Elements found :
.
HKCU\SOFTWARE\SWEETIE
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKLM\SOFTWARE\Macrogaming
HKLM\~\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\~\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\Program Files\Macrogaming
C:\Program Files\Macrogaming\SweetIM
C:\Program Files\Macrogaming\SweetIM\conf
C:\Program Files\Macrogaming\SweetIM\data
C:\Program Files\Macrogaming\SweetIM\conf\users
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr
C:\Program Files\Macrogaming\SweetIM\conf\users\main_user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\lastuse_SpecialFX.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\lol_3818@hotmail.fr\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\turquoise37@hotmail.fr\user_config.xml
C:\Program Files\Macrogaming\SweetIM\data\contentdb
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010859.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020158.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050001.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050002.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\cache_indx.dat
+--------------------| ADDED SCAN :
+---------- Scanning prefs.js ... ( # Mozilla User Preferences )
..\r43dkw3q.default\prefs.js :
~~~~ Mozilla FireFox version [Unable to get version] ~~~~
* Browser Search Default Engine: "Yahoo"
* Browser Search Selected Engine: "Yahoo"
* Browser Search Default Url: "https://www.google.com/webhp?lr=&ie=UTF-8&oe=UTF-8&gws_rd=ssl"
* Browser Startup HomePage: "http://eo.st"
.
FOUND - user_pref("browser.startup.homepage", "http://eo.st");
+---------------------------------------------------------------------------+
~~~~ Internet Explorer version 7.0.5730.11 ~~~~
+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]
Start Page : hxxp://www.google.fr/
+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]
Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
+---------------------------------------------------------------------------+
[~5369 bytes] - "C:\AD-report-Scan-07.01.2009.log"
[~5153 bytes] - "C:\AD-report-Scan-14.01.2009.log"
# END at: 8:30:20 | 14/01/2009 - Time elapsed: 58.4 seconds
+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 96 lines ]
+---------------------------------------------------------------------------+
Re,
▶ /!\ Déconnectes toi et fermes toutes applications en cours /!\
▶ Relances "Ad-remover" : au menu principal choisi l'option "B" .
http://apu.mabul.org/up/apu/2008/11/19/img-221318q2g03.jpg
Il faut taper un chiffre et valider systématiquement celui-ci par ENTREE.
▶ Ensuite coche:
Eorezo
FunWeb
ItsTV
Sweetim
▶ Puis "S"
▶ le programme va travailler ...
▶ Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...
( le rapport est sauvegardé aussi sous C:\Ad-report.log )
/!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\
▶ /!\ Déconnectes toi et fermes toutes applications en cours /!\
▶ Relances "Ad-remover" : au menu principal choisi l'option "B" .
http://apu.mabul.org/up/apu/2008/11/19/img-221318q2g03.jpg
Il faut taper un chiffre et valider systématiquement celui-ci par ENTREE.
▶ Ensuite coche:
Eorezo
FunWeb
ItsTV
Sweetim
▶ Puis "S"
▶ le programme va travailler ...
▶ Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...
( le rapport est sauvegardé aussi sous C:\Ad-report.log )
/!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\
Re,
Tu tape les lettres correspondant a "eorezo" it's tv,...etc,
Ensuite a chaque fois que tu tape le BN° correspoondant tu tape sur entrer et ensuite tu tape S.
Tu tape les lettres correspondant a "eorezo" it's tv,...etc,
Ensuite a chaque fois que tu tape le BN° correspoondant tu tape sur entrer et ensuite tu tape S.
------ Logfile of AD-Remover 1.0.8.9 by C_XX | ONLY XP/VISTA -------
*** Limited to ***
Eorezo
Everest Casino/Everest Poker
It's TV
Sweetim
******************
# START AT: 15:27:55 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 47
(!) ---- IE start pages reset
+--------------------| Eorezo Elements Deleted :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo
+--------------------| Everest Casino/Everest Poker Elements Deleted :
.
.
+--------------------| It's TV Elements Deleted :
HKCU\SOFTWARE\ItsLabel
.
C:\Documents and Settings\berlandis\Application Data\ItsLabel
+--------------------| Sweetim Elements Deleted :
.
HKLM\~\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\~\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
HKCU\SOFTWARE\SWEETIE
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKLM\SOFTWARE\Macrogaming
.
C:\Program Files\Macrogaming
(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.
+--------------------| ADDED SCAN :
+---------- Scanning prefs.js ... ( # Mozilla User Preferences )
..\r43dkw3q.default\prefs.js :
~~~~ Mozilla FireFox version [Unable to get version] ~~~~
* Browser Search Default Engine: "Yahoo"
* Browser Search Selected Engine: "Yahoo"
* Browser Search Default Url: "https://www.google.com/webhp?lr=&ie=UTF-8&oe=UTF-8&gws_rd=ssl"
* Browser Startup HomePage: "http://eo.st"
.
*** Limited to ***
Eorezo
Everest Casino/Everest Poker
It's TV
Sweetim
******************
# START AT: 15:27:55 | Mer 14/01/2009 | Microsoft® Windows XP™ SP3 (v5.1.2600)
# BOOT MODE: Normal
# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
# PC: D8HM0L1J | USER: berlandis ( Current user is an administrator)
# DRIVE(S):
- C:\ (File System: NTFS)
# System Drive: C:\
# Windows Directory: C:\WINDOWS\
# System Directory: C:\WINDOWS\system32\
--- RUNNING PROCESSES: 47
(!) ---- IE start pages reset
+--------------------| Eorezo Elements Deleted :
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\SOFTWARE\EoRezo
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\SOFTWARE\EoRezo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
.
C:\Program Files\EoRezo
C:\Documents and Settings\berlandis\Application Data\EoRezo
+--------------------| Everest Casino/Everest Poker Elements Deleted :
.
.
+--------------------| It's TV Elements Deleted :
HKCU\SOFTWARE\ItsLabel
.
C:\Documents and Settings\berlandis\Application Data\ItsLabel
+--------------------| Sweetim Elements Deleted :
.
HKLM\~\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\~\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
HKCU\SOFTWARE\SWEETIE
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
HKLM\SOFTWARE\Macrogaming
.
C:\Program Files\Macrogaming
(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.
+--------------------| ADDED SCAN :
+---------- Scanning prefs.js ... ( # Mozilla User Preferences )
..\r43dkw3q.default\prefs.js :
~~~~ Mozilla FireFox version [Unable to get version] ~~~~
* Browser Search Default Engine: "Yahoo"
* Browser Search Selected Engine: "Yahoo"
* Browser Search Default Url: "https://www.google.com/webhp?lr=&ie=UTF-8&oe=UTF-8&gws_rd=ssl"
* Browser Startup HomePage: "http://eo.st"
.
Re,
Redémarre ton pc normalement et refait un rapport avec RSIT.
merci d'avoir prévenue chimay.
Redémarre ton pc normalement et refait un rapport avec RSIT.
merci d'avoir prévenue chimay.
Logfile of random's system information tool 1.05 (written by random/random)
Run by berlandis at 2009-01-14 15:49:58
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (20% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\findstr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [Film Up] C:\DOCUME~1\LAURA\APPLIC~1\PLANBI~1\SOFTWINBUILD.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray (User 'LAURA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Run by berlandis at 2009-01-14 15:49:58
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (20% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\findstr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [Film Up] C:\DOCUME~1\LAURA\APPLIC~1\PLANBI~1\SOFTWINBUILD.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe (User 'LAURA')
O4 - HKUS\S-1-5-21-1374290520-151700281-2192659466-1008\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray (User 'LAURA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Re,
Supprime norton.
comment le faire proprement
Ensuite:
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:files
c:\program files\planbi~1\softwinbuild.exe
c:\program files\messengerskinner\messengerskinner.exe
c:\windows\lbtwiz.exe
:commands
[emptytemp]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
Supprime norton.
comment le faire proprement
Ensuite:
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:files
c:\program files\planbi~1\softwinbuild.exe
c:\program files\messengerskinner\messengerskinner.exe
c:\windows\lbtwiz.exe
:commands
[emptytemp]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
PRODUCT(S)
Norton Internet Security 2000 1.0
Norton Personal Firewall 2000 2.0
Norton Internet Security 2000 2.0
Norton Internet Security Family Edition 2000 2.0
Norton Personal Firewall 2001 2.5
Norton Internet Security 2001 2.5
Norton Internet Security Family Edition 2001 2.5
Norton Personal Firewall 2001 3.0
Norton Internet Security 2001 3.0
Norton Internet Security Family Edition 2001 3.0
Norton Personal Firewall 2002 4.0
Norton Internet Security 2002 4.0
Norton Internet Security Professional 2002 4.5
Norton Personal Firewall 2003 6.0
Norton Internet Security 2003 6.0
Norton Internet Security Professional 2003 6.0
INSTALLED DIRECTORY
ACTIVE SERVICES/PROCESSES
Stopping SymPxSvc
Stopping NISSERV
Stopping NISUM
Stopping ccEvtMgr
Stopping ccPwdSvc
Stopping ccPxySvc
WINDOWS INSTALLER INFORMATION
Remove Windows Installer Information for Norton Internet Security 1.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E16453A0-3AED-11D3-AF47-00600811C705}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C26B870B-08E6-442A-AAE3-6A250CCFE94E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7C1A7F8E-3662-4B0C-A573-C680C043E80E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ED4D92D3-7DE4-49AF-8B1C-CA1B7B9274D2}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF8FE655-CAD3-4E71-AC80-140A7F842CB3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C02388E1-C0E3-462E-BDC8-7E1D56D8AC4D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9209615F-276E-4406-8607-DF2B3C9F0F34}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCAE58EF-511C-44D7-81F2-D32876A04EEA}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0AE91EA0-83D4-49B9-ADF7-B769F7D091A4}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D17CC1F3-FC25-41B6-9F9F-68295B4E177B}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D54BDAC-C362-4849-B52F-814319CF5057}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 4.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{72AAF846-3C35-4391-9459-CC7B6EC7E07A}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15BFECE8-A100-4861-B92B-1EFF76683C23}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{93DF5BBA-2992-482F-B11D-91027EC8AC7D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Total references deleted = 0
LIVEUPDATE
Unregister {8BBAA23E-A16C-4899-B3BD-CA5FE6A07011} with LiveUpdate
Unregister {A0B7DE31-6FB5-4e1f-8F82-F1E5E9F968EB} with LiveUpdate
Unregister {BAAFC3EB-C2A9-4572-983A-54D1FFC75B18} with LiveUpdate
Unregister {C0DA9CA0-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA1-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA2-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA3-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {2A4E728E-ECD1-4ec8-A451-2D719C7EEF10} with LiveUpdate
Unregister {5911B56B-54AA-4678-9933-9413CB93B23C} with LiveUpdate
Unregister {6E34DCC1-B194-11d2-A11E-00409500AD7D} with LiveUpdate
Unregister {DC4CC242-AB75-4bfe-A51E-4CE500ADD552} with LiveUpdate
Unregister {94014D45-7F26-48ca-9CE5-79E39A01A6A6} with LiveUpdate
LIVESUBSCRIBE
Failed to Unload LiveReg on Uninstall
Unregister B211DA60-6B70-11d3-9775-005004D12CC3 with LiveSubscribe
SERVICE DEPENDENCIES
Removing SymEvent IDs
SymEvent ID not found: SymNetDrv
SERVICES
REGISTRY KEYS
Delete Software\Symantec\IAM
Delete Software\Symantec\IAM.tmp
Delete Software\Symantec\IAM.old
Delete Software\Symantec\SymReg
Delete Software\Symantec\ccReg
Delete Software\Symantec\CommonClient
COM SERVERS AND FILE EXTENSIONS
SHORTCUTS
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security Professional
FILES AND DIRECTORIES
File doesn't exist: C:\WINDOWS\system32\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDSCo.sys
File doesn't exist: C:\WINDOWS\system32\sr.dat
File doesn't exist: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\deleteme.bat
File doesn't exist: C:\WINDOWS\temp\deleteme.bat
File doesn't exist: C:\WINDOWS\system32\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.INF
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.CAT
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDRV.SYS
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\drivers\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\sr2.dat
File doesn't exist: C:\WINDOWS\system32\SymNeti.dll
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SymTdiRg.exe
File doesn't exist: %SYMC_SRD%\Default.rul
File doesn't exist: %SYMC_SRD%\Persist.dat
File doesn't exist: C:\WINDOWS\system32\ccTrust.dll
File doesn't exist: C:\WINDOWS\system32\ccPasswd.dll
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
Norton Internet Security 2000 1.0
Norton Personal Firewall 2000 2.0
Norton Internet Security 2000 2.0
Norton Internet Security Family Edition 2000 2.0
Norton Personal Firewall 2001 2.5
Norton Internet Security 2001 2.5
Norton Internet Security Family Edition 2001 2.5
Norton Personal Firewall 2001 3.0
Norton Internet Security 2001 3.0
Norton Internet Security Family Edition 2001 3.0
Norton Personal Firewall 2002 4.0
Norton Internet Security 2002 4.0
Norton Internet Security Professional 2002 4.5
Norton Personal Firewall 2003 6.0
Norton Internet Security 2003 6.0
Norton Internet Security Professional 2003 6.0
INSTALLED DIRECTORY
ACTIVE SERVICES/PROCESSES
Stopping SymPxSvc
Stopping NISSERV
Stopping NISUM
Stopping ccEvtMgr
Stopping ccPwdSvc
Stopping ccPxySvc
WINDOWS INSTALLER INFORMATION
Remove Windows Installer Information for Norton Internet Security 1.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E16453A0-3AED-11D3-AF47-00600811C705}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C26B870B-08E6-442A-AAE3-6A250CCFE94E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7C1A7F8E-3662-4B0C-A573-C680C043E80E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ED4D92D3-7DE4-49AF-8B1C-CA1B7B9274D2}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF8FE655-CAD3-4E71-AC80-140A7F842CB3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C02388E1-C0E3-462E-BDC8-7E1D56D8AC4D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9209615F-276E-4406-8607-DF2B3C9F0F34}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCAE58EF-511C-44D7-81F2-D32876A04EEA}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0AE91EA0-83D4-49B9-ADF7-B769F7D091A4}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D17CC1F3-FC25-41B6-9F9F-68295B4E177B}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D54BDAC-C362-4849-B52F-814319CF5057}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 4.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{72AAF846-3C35-4391-9459-CC7B6EC7E07A}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15BFECE8-A100-4861-B92B-1EFF76683C23}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{93DF5BBA-2992-482F-B11D-91027EC8AC7D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Total references deleted = 0
LIVEUPDATE
Unregister {8BBAA23E-A16C-4899-B3BD-CA5FE6A07011} with LiveUpdate
Unregister {A0B7DE31-6FB5-4e1f-8F82-F1E5E9F968EB} with LiveUpdate
Unregister {BAAFC3EB-C2A9-4572-983A-54D1FFC75B18} with LiveUpdate
Unregister {C0DA9CA0-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA1-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA2-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA3-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {2A4E728E-ECD1-4ec8-A451-2D719C7EEF10} with LiveUpdate
Unregister {5911B56B-54AA-4678-9933-9413CB93B23C} with LiveUpdate
Unregister {6E34DCC1-B194-11d2-A11E-00409500AD7D} with LiveUpdate
Unregister {DC4CC242-AB75-4bfe-A51E-4CE500ADD552} with LiveUpdate
Unregister {94014D45-7F26-48ca-9CE5-79E39A01A6A6} with LiveUpdate
LIVESUBSCRIBE
Failed to Unload LiveReg on Uninstall
Unregister B211DA60-6B70-11d3-9775-005004D12CC3 with LiveSubscribe
SERVICE DEPENDENCIES
Removing SymEvent IDs
SymEvent ID not found: SymNetDrv
SERVICES
REGISTRY KEYS
Delete Software\Symantec\IAM
Delete Software\Symantec\IAM.tmp
Delete Software\Symantec\IAM.old
Delete Software\Symantec\SymReg
Delete Software\Symantec\ccReg
Delete Software\Symantec\CommonClient
COM SERVERS AND FILE EXTENSIONS
SHORTCUTS
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Personal Firewall
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security Family Edition
File doesn't exist: C:\Documents and Settings\All Users\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Bureau\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Démarrage\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\berlandis\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\HelpAssistant\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\Invit‚\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\LAURA\Menu Démarrer\Programmes\Norton Internet Security Professional
File doesn't exist: C:\Documents and Settings\SUPPORT_388945a0\Menu Démarrer\Programmes\Norton Internet Security Professional
FILES AND DIRECTORIES
File doesn't exist: C:\WINDOWS\system32\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDSCo.sys
File doesn't exist: C:\WINDOWS\system32\sr.dat
File doesn't exist: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\deleteme.bat
File doesn't exist: C:\WINDOWS\temp\deleteme.bat
File doesn't exist: C:\WINDOWS\system32\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.INF
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.CAT
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDRV.SYS
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\drivers\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\sr2.dat
File doesn't exist: C:\WINDOWS\system32\SymNeti.dll
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SymTdiRg.exe
File doesn't exist: %SYMC_SRD%\Default.rul
File doesn't exist: %SYMC_SRD%\Persist.dat
File doesn't exist: C:\WINDOWS\system32\ccTrust.dll
File doesn't exist: C:\WINDOWS\system32\ccPasswd.dll
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
Error: Unable to interpret <files > in the current context!
Error: Unable to interpret <c:\program files\planbi~1\softwinbuild.exe > in the current context!
Error: Unable to interpret <c:\program files\messengerskinner\messengerskinner.exe > in the current context!
Error: Unable to interpret <c:\windows\lbtwiz.exe > in the current context!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\off60.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DF751D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DFECE6.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_3d0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01142009_160103
Files moved on Reboot...
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\off60.tmp not found!
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DF751D.tmp not found!
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DFECE6.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_3d0.dat not found!
Error: Unable to interpret <c:\program files\planbi~1\softwinbuild.exe > in the current context!
Error: Unable to interpret <c:\program files\messengerskinner\messengerskinner.exe > in the current context!
Error: Unable to interpret <c:\windows\lbtwiz.exe > in the current context!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\off60.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DF751D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DFECE6.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_3d0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01142009_160103
Files moved on Reboot...
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\off60.tmp not found!
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DF751D.tmp not found!
File C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\~DFECE6.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_3d0.dat not found!
Logfile of random's system information tool 1.05 (written by random/random)
Run by berlandis at 2009-01-14 18:56:49
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:56, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Run by berlandis at 2009-01-14 18:56:49
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:56, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Re,
▶ Télécharge sur ton bureau MSNFix
▶ Enregistrez le fichier sur votre bureau.
▶ Ne pas double-cliquer sur le fichier
▶ Faites un clic droit sur le fichier puis Extraire tout, le but étant de récupérer un dossier MSNFix
▶ Double-cliquez sur le dossier MSNFix afin de l'ouvrir
▶ Vous trouverez dedans un nouveau dossier ainsi qu'un fichier MSNFix.bat (le .bat peut ne pas apparaître chez vous).
▶ Double-cliquez sur MSNFix.bat
▶ Exécute l'option R.
Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage.
Note : Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur.
- Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.t, poste-le.
▶ Télécharge sur ton bureau MSNFix
▶ Enregistrez le fichier sur votre bureau.
▶ Ne pas double-cliquer sur le fichier
▶ Faites un clic droit sur le fichier puis Extraire tout, le but étant de récupérer un dossier MSNFix
▶ Double-cliquez sur le dossier MSNFix afin de l'ouvrir
▶ Vous trouverez dedans un nouveau dossier ainsi qu'un fichier MSNFix.bat (le .bat peut ne pas apparaître chez vous).
▶ Double-cliquez sur MSNFix.bat
▶ Exécute l'option R.
Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage.
Note : Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur.
- Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.t, poste-le.
Je pense que c'est pas ça que tu me demandes!mais trouve pas ailleurs, ou alors avec un autre descriptif!
read file error: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
read file error: C:\WINDOWS\system32\cftmon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\winlogon.exe, Le fichier spécifié est introuvable.
read file error: C:\DOCUME~1\BERLAN~1\LOCALS~1\Temp\services.exe, Le fichier spécifié est introuvable.
read file error: C:\WINDOWS\system32\cftmon.exe, Le fichier spécifié est introuvable.
Re,
regarde la
regarde la
Mon Cher V-X, explique-moi brièvement pourquoi depuis une semaine je me balade avec vous pour "réparer" mon PC pour 1 truc simple?
Certes tu fais preuve de bcp + de patience que tes collègues virtuels, mais bon!! même si j'essaie de suivre ts tes protocoles et conseils bienveillants, je dérape à 1 moment ou 1 autre...simplifions...tu penses pas?
BISE
Certes tu fais preuve de bcp + de patience que tes collègues virtuels, mais bon!! même si j'essaie de suivre ts tes protocoles et conseils bienveillants, je dérape à 1 moment ou 1 autre...simplifions...tu penses pas?
BISE
COUCOU RE...est-ce le bon?
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
[C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
[C:\WINDOWS\system32\WinFXDocObj.exe] 660336AD0305C852122C5EEBBACE9BAF
[C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
[C:\WINDOWS\system32\winlogon.exe] DD73D6B9F6B4CB630CF35B438B540174
[C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
[C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
[C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
[C:\WINDOWS\system32\winver.exe] 61E80B60CD30D995E80702623BE47B9D
Logfile of random's system information tool 1.05 (written by random/random)
Run by berlandis at 2009-01-15 18:24:10
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24, on 15/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Run by berlandis at 2009-01-15 18:24:10
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 29 GB (39%) free of 73 GB
Total RAM: 510 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24, on 15/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\berlandis\Bureau\RSIT.exe
C:\Program Files\trend micro\berlandis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/43.10/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://turquoise37.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1230838878778&h=9d7f19b45b3ed7e9fb33cfcd8bb6a34f/&filename=jinstall-6u11-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://express.foto.com/SFUploader/SpeedUploader.cab
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Re,
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:files
c:\windows\lbtwiz.exe
:commands
[purity]
[emptytemp]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :
:files
c:\windows\lbtwiz.exe
:commands
[purity]
[emptytemp]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
File/Folder c:\windows\lbtwiz.exe not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_69c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01152009_183458
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_69c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01152009_183458