- Fenêtres pub
- Supprimer pub youtube - Accueil - Streaming
- Pub par sms - Guide
- Logiciel anti pub - Télécharger - Web & Internet
- Stop pub gratuit - Télécharger - Divers Utilitaires
- Mon clavier n'écrit plus et ouvre des fenetres ✓ - Forum Windows Vista
85 réponses
- 1
- 2
- 3
- 4
- 5
Problème : Des fenêtres publicitaires s'ouvrent sur un système Windows XP avec Mozilla Firefox et Avast, et la demande porte sur la suppression de ces infections et des pubs persistantes.
Plusieurs réponses proposent des outils dédiés, notamment ComboFix et Toolbar-S&D, avec des avertissements sur les risques et la nécessité de désactiver temporairement l'antivirus ou la protection résidente pour que le nettoyage soit efficace.
D'autres interventions évoquent des rapports d'analyse et des nettoyages complémentaires, notamment la vérification des extensions et des cookies, afin d'éviter que des résidus réinfectent le système.
Peux tu faire un scan hijack this,
Fais "do a scan and save a log",copies le rapport (ctrl+c) et postes le (ctrl+v) sur cette page
http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option "1" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
rapport:
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology ML-32 )
BIOS : Ver 1.00PARTTBLh
USER : Danny ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090207-0] 4.8.1296 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:53 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 08/02/2009|15:00 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\DOCUME~1\Danny\Cookies\danny@antivirusgolden[1].txt
C:\DOCUME~1\Danny\Cookies\danny@code-crawler[2].txt
C:\DOCUME~1\Danny\Cookies\danny@hotbar[2].txt
C:\DOCUME~1\Danny\Cookies\danny@myway[1].txt
C:\DOCUME~1\Danny\Cookies\danny@mywebsearch[1].txt
C:\DOCUME~1\Danny\Cookies\danny@h.starware[1].txt
C:\DOCUME~1\Danny\Cookies\danny@try.starware[1].txt
C:\DOCUME~1\Danny\LOCALS~1\Temp\ICD1.tmp
-----------\\ Extensions
(Danny) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Danny) - {7E77F5DF-8022-40e3-9122-F03DEBEFC43B} => psicotsi
(Danny) - {90ab4b7a-dfc8-420b-a205-eae16593e719} => skillraise
(Danny) - {9d1f059c-cada-4111-9696-41a62d64e3ba} => foxtrick
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sports.fr/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchAssistant"="http://search.bearshare.com/sidebar.html?src=ssb"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page"="https://fr.yahoo.com/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game
1 - "C:\ToolBar SD\TB_1.txt" - 08/02/2009|15:08 - Option : [1]
-----------\\ Fin du rapport a 15:08:11,70
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre questionTélécharge de AD-Remover de Cyrildu17 / C_XX) sur ton Bureau.
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
/!\ Déconnecte-toi et ferme toutes applications en cours /!\
- Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
- Double-clique sur l'icône Ad-remover située sur ton Bureau.
- Au menu principal, choisis l'option "A".
- Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
Note :
"Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology ML-32 )
BIOS : Ver 1.00PARTTBLh
USER : Danny ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090207-0] 4.8.1296 (Activated)
C:\ (Local Disk) - NTFS - Total:74 Go (Free:53 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 08/02/2009|15:18 )
-----------\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@antivirusgolden[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@code-crawler[2].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@hotbar[2].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@myway[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@mywebsearch[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@h.starware[1].txt
Supprime! - C:\DOCUME~1\Danny\Cookies\danny@try.starware[1].txt
Supprime! - C:\DOCUME~1\Danny\LOCALS~1\Temp\ICD1.tmp
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Danny) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Danny) - {7E77F5DF-8022-40e3-9122-F03DEBEFC43B} => psicotsi
(Danny) - {90ab4b7a-dfc8-420b-a205-eae16593e719} => skillraise
(Danny) - {9d1f059c-cada-4111-9696-41a62d64e3ba} => foxtrick
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.sports.fr/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchAssistant"="http://search.bearshare.com/sidebar.html?src=ssb"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game
1 - "C:\ToolBar SD\TB_1.txt" - 08/02/2009|15:08 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 08/02/2009|15:23 - Option : [2]
-----------\\ Fin du rapport a 15:23:42,84
Cracks & Keygens ..
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\bounty.properties
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\crackshot_maude.png
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\gully.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\high_shooter.game
C:\DOCUME~1\Danny\Application Data\bang\rsrc\bounties\frontier_town\most_wanted\extreme\crackshot_maude\keep_em.game
Ensuite,fais ad remover comme indiqué sur le post 7
Updated by C_XX on 07/02/2009 at 14:30
Start at: 15:33:43 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 48
+--------------------| Boonty/Boonty Games Elements Found:
.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt
+--------------------| Eorezo Elements Found:
.
+--------------------| Infected Poker Softwares Elements Found:
HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\Everest Poker\data
C:\Program Files\Everest Poker\history
C:\Program Files\Everest Poker\data\fonts
C:\Program Files\Everest Poker\data\mp-lobby
C:\Program Files\Everest Poker\data\mp-poker
C:\Program Files\Everest Poker\data\shared
C:\Program Files\Everest Poker\data\startup
C:\Program Files\Everest Poker\data\mp-poker\background
C:\Program Files\Everest Poker\data\mp-poker\fr
C:\Program Files\Everest Poker\data\shared\fr
C:\Program Files\Everest Poker\data\shared\shared
C:\Program Files\Everest Poker\data\shared\shared\bitmaps
C:\Program Files\Everest Poker\data\shared\shared\sounds
C:\Program Files\Everest Poker\data\startup\en
C:\Program Files\Everest Poker\data\startup\fr
C:\Program Files\Everest Poker\data\startup\shared
C:\Program Files\Everest Poker\data\startup\shared\bitmaps
C:\Program Files\Everest Poker\data\startup\shared\icons
C:\Program Files\Everest Poker\data\startup\shared\sounds
C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\images
C:\Program Files\PartyGaming\Language
C:\Program Files\PartyGaming\PartyCasino
C:\Program Files\PartyGaming\PartyPoker
C:\Program Files\PartyGaming\tmpUpgrade
C:\Program Files\PartyGaming\Language\en_US
C:\Program Files\PartyGaming\Language\fr_FR
C:\Program Files\PartyGaming\Language\en_US\temp
C:\Program Files\PartyGaming\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyCasino\Images
C:\Program Files\PartyGaming\PartyCasino\Language
C:\Program Files\PartyGaming\PartyCasino\Temp
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE
C:\Program Files\PartyGaming\PartyCasino\Language\en_US
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE\images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\articles
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\lobby
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyPoker\Images
C:\Program Files\PartyGaming\PartyPoker\Language
C:\Program Files\PartyGaming\PartyPoker\NewSounds
C:\Program Files\PartyGaming\PartyPoker\PokerTrainer
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade
C:\Program Files\PartyGaming\PartyPoker\Images\NewGameTable
C:\Program Files\PartyGaming\PartyPoker\Language\en_US
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images\NewGameTable
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt
+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Found:
.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt
+--------------------| It's TV Elements Found:
.
+--------------------| Sweetim Elements Found:
HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
.
+--------------------| Added Scan:
---- Mozilla FireFox Version 3.0.6 ----
ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.
---- Internet Explorer Version 6.0.2900.2180 ----
+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr
+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.google.com
Start page: hxxp:/www.msn.com
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: hxxp:/ieframe.dll
+---------------------------------------------------------------------------+
[~7360 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-
End at: 15:37:01 | 08/02/2009
.
+--------------------| E.O.F - 142 Lines
.
1)Télécharge Toolbar-S&D (Team IDN) sur ton Bureau :
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option "1" puis valide en appuyant sur "Entrée".
! Ne ferme pas la fenêtre lors de la suppression !
Un rapport sera généré, poste son contenu ici.
Telecharges NAVILOG
Clique sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Clique sur navilog1.exe pour télécharger navilog1
Choisis Enregistrer
et enregistre-le sur ton bureau.
/ !\ Déconnecte-toi et désactive ton antivirus et antispyware résident pour que Navilog1 puisse s'exécuter normalement. /!\
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valide.
Patiente jusqu'au message :
*** Analyse Terminée le ..... ***
Appuie sur une touche comme demandé, le bloc note va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le bloc note.
Le rapport est en outre sauvegardé à la racine du disque (C:\fixnavi.txt)
poste le rapport obtenu
------- LOGFILE OF AD-REMOVER 1.1.0.9 | ONLY XP/VISTA -------
Updated by C_XX on 07/02/2009 at 14:30
Start at: 15:33:43 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 48
+--------------------| Boonty/Boonty Games Elements Found:
.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt
+--------------------| Eorezo Elements Found:
.
+--------------------| Infected Poker Softwares Elements Found:
HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\Everest Poker\data
C:\Program Files\Everest Poker\history
C:\Program Files\Everest Poker\data\fonts
C:\Program Files\Everest Poker\data\mp-lobby
C:\Program Files\Everest Poker\data\mp-poker
C:\Program Files\Everest Poker\data\shared
C:\Program Files\Everest Poker\data\startup
C:\Program Files\Everest Poker\data\mp-poker\background
C:\Program Files\Everest Poker\data\mp-poker\fr
C:\Program Files\Everest Poker\data\shared\fr
C:\Program Files\Everest Poker\data\shared\shared
C:\Program Files\Everest Poker\data\shared\shared\bitmaps
C:\Program Files\Everest Poker\data\shared\shared\sounds
C:\Program Files\Everest Poker\data\startup\en
C:\Program Files\Everest Poker\data\startup\fr
C:\Program Files\Everest Poker\data\startup\shared
C:\Program Files\Everest Poker\data\startup\shared\bitmaps
C:\Program Files\Everest Poker\data\startup\shared\icons
C:\Program Files\Everest Poker\data\startup\shared\sounds
C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\images
C:\Program Files\PartyGaming\Language
C:\Program Files\PartyGaming\PartyCasino
C:\Program Files\PartyGaming\PartyPoker
C:\Program Files\PartyGaming\tmpUpgrade
C:\Program Files\PartyGaming\Language\en_US
C:\Program Files\PartyGaming\Language\fr_FR
C:\Program Files\PartyGaming\Language\en_US\temp
C:\Program Files\PartyGaming\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyCasino\Images
C:\Program Files\PartyGaming\PartyCasino\Language
C:\Program Files\PartyGaming\PartyCasino\Temp
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE
C:\Program Files\PartyGaming\PartyCasino\Language\en_US
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR
C:\Program Files\PartyGaming\PartyCasino\Language\de_DE\images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\articles
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\lobby
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\en_US\Images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyCasino\Language\es_ES\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\blackjack\blackjack
C:\Program Files\PartyGaming\PartyCasino\Language\fr_FR\images\games\cardgames\multiplayerbj\multiplayerblackjack
C:\Program Files\PartyGaming\PartyPoker\Images
C:\Program Files\PartyGaming\PartyPoker\Language
C:\Program Files\PartyGaming\PartyPoker\NewSounds
C:\Program Files\PartyGaming\PartyPoker\PokerTrainer
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade
C:\Program Files\PartyGaming\PartyPoker\Images\NewGameTable
C:\Program Files\PartyGaming\PartyPoker\Language\en_US
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\Articles
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\temp
C:\Program Files\PartyGaming\PartyPoker\Language\fr_FR\images\NewGameTable
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt
+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Found:
.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt
+--------------------| It's TV Elements Found:
.
+--------------------| Sweetim Elements Found:
HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
.
+--------------------| Added Scan:
---- Mozilla FireFox Version 3.0.6 ----
ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.
---- Internet Explorer Version 6.0.2900.2180 ----
+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr
+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/www.google.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.sports.fr
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.google.com
Start page: hxxp:/www.msn.com
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: hxxp:/ieframe.dll
+---------------------------------------------------------------------------+
[~7360 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-
End at: 15:37:01 | 08/02/2009
.
+--------------------| E.O.F - 142 Lines
ce que je n'arrive pas à faire, c'est ça:
Relances ad remover,fais A,puis cliques sur 1,3,4,6 puis S et postes moi le rapport.
moi je tape A, puis enter, puis le programme commence à analyser le systeme
je sais pas comment je dois faire pour cliquer 1,3,4,6 et S
puis quand j'instalerai NAVILOG, je dois désactiver mon anti-virus, c'est à dire mon avast:
pour le désactiver, je clique sur ' arreter la protection résidente' ?
Updated by C_XX on 07/02/2009 at 14:30
*** LIMITED TO ***
Boonty/BoontyGames
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
Sweetim
******************
Start at: 16:50:25 | Dim 08/02/2009 | Microsoft® Windows XP™ SP2 (V5.1.2600)
Boot mode: Normal
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Pc: FUJITSU-57A07E7 | User: Danny ( Current user is an administrator)
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\
--- Running Processes: 49
(!) ---- IE start pages/Tabs reset
+--------------------| Boonty/Boonty Games Elements Deleted :
.
.
C:\Documents and Settings\Danny\Cookies\danny@boonty.122.2o7[1].txt
+--------------------| Infected Poker Softwares Elements Deleted :
HKCU\Software\PartyGaming
HKLM\Software\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PartyPoker
.
C:\Program Files\Everest Poker
C:\Program Files\PartyGaming
C:\Documents and Settings\Danny\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
C:\Documents and Settings\Danny\Menudm~1\Progra~1\PartyPoker
C:\Documents and Settings\Danny\Cookies\danny@partygaming.122.2o7[1].txt
C:\Documents and Settings\Danny\Cookies\danny@partypoker[2].txt
+--------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :
.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df}
.
C:\Documents and Settings\Danny\Cookies\danny@webfetti[1].txt
+--------------------| Sweetim Elements Deleted :
HKCR\Interface\{0C1CF2DF-05A3-4FEF-8CD4-F5CFC4355A16}
HKCR\Typelib\{710993A2-4F87-41D7-B6FE-F5A20368465F}
HKLM\SOFTWARE\Classes\CLSID\{06ADA938-0FB0-4BC0-B19B-0A38AB17F182}
.
(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.
+--------------------| Added Scan :
---- Mozilla FireFox Version 3.0.6 ----
ProfilePath: sjbzn96h.default
.
Prefs.js: Browser.Search.DefaultEngineName: "Google"
Prefs.js: Browser.Search.DefaultUrl: "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
.
.
.
.
.
---- Internet Explorer Version 6.0.2900.2180 ----
+-[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/go.microsoft.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.microsoft.com
+-[HKEY_USERS\S-1-5-21-602162358-152049171-725345543-1005\..\Internet Explorer\Main]
Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
SearchAssistant: hxxp:/search.bearshare.com
Search bar: hxxp:/go.microsoft.com
Search Page: hxxp:/www.google.com
Start page: hxxp:/www.microsoft.com
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp:/www.microsoft.com
Default_Search_URL: hxxp:/www.microsoft.com
Search bar: hxxp:/search.msn.com
Search Page: hxxp:/www.microsoft.com
Start page: hxxp:/fr.msn.com
+-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: hxxp:/ieframe.dll
+---------------------------------------------------------------------------+
[~3628 Bytes] - "C:\Ad-Report-Clean-08.02.2009.log"
[~7496 Bytes] - "C:\Ad-Report-Scan-08.02.2009.log"
-
End at: 17:01:04 | 08/02/2009
.
+--------------------| E.O.F - 84 Lines
.
- 1
- 2
- 3
- 4
- 5
Scan saved at 14:54:31, on 08/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sports.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O5 "LPT1:" /M "Stylus CX3600"
O4 - HKLM\..\Run: [Youtube] C:\Program Files\Youtube\Youtube.exe
O4 - HKLM\..\Run: [bait deaf idle setup] C:\Documents and Settings\All Users\Application Data\Htm Support Bait Deaf\dead scr.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series (Copie 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P36 "EPSON Stylus CX3600 Series (Copie 1)" /O6 "USB001" /M "Stylus CX3600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Proc Deaf Delete Peak] C:\Documents and Settings\All Users\Application Data\file joy proc deaf\01 extra.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Peak new] C:\DOCUME~1\Danny\APPLIC~1\FIVEBO~1\closemfcd.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Youtube.lnk = C:\Program Files\Youtube\Youtube.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZCxdm490YYLU
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe