VIRUS & INTERNET = BIG BAZAR

GUGUS -  
Redbart Messages postés 20952 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,
AVAST a detecté les infections suivantes :
win 32:Adaware-gen & win 32:trojan-gen dans morpheus\morpheustoolbar.exe
== > mis en quarantaine puis supprimés
et une erreur 42145 dans downloads\pllangs.exe (archive d'installateur corrompue) ==> sais pas quoi faire ?
MALWAREBYTE a détecté VUNDO ==> mis en quarantaine et supprimé
après relancer avast et malwarebyte ==> tout a l'air OK

mais pas de connexion .... c'est pas la box (confirmé par sfr + ordi port a la connexion)

alors je poste le log de HIJACKTHIS

merci de m'aider ....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:07:36, on 13/03/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Talkway\vmtalk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Microsoft Money\System\reminder.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = Download Directory
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\Windows\p_981116.exe /Q:A
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [vmtalk] C:\Program Files\Common Files\Talkway\vmtalk.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [HPSoftwareUpdate] C:\Program Files\HP\HP Software Update\HPWUCli.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

--
End of file - 9647 bytes
Configuration: Windows Vista / Internet Explorer 7.0

3 réponses

  1. Redbart Messages postés 20952 Date d'inscription   Statut Membre Dernière intervention   3 382
     
    Bsr
    3 anti virus (+ 1 scan online BD)
    3 anti spyware
    1 pare feu

    c vraiment de la malchance

    ça m'étonne que mbam n'ai pas détecté "autres choses" -fait une mise à jour - et relance
    post le rapport
    0
    1. GUGUS
       
      Salut,

      peut pas faire une mise à jour car j'ai pas de connexion !!! et je sais pas pourquoi ?
      ou aors je j'utilise le portable de ma fille ?
      0
  2. GUSGUS
     
    bonsoir,
    je t'envoi les logs de MBMA de spybot et d'hijakthis que j'ai fais ce week end
    mon ordi rame à mort
    j'attend ton aide merci d'avance.

    Malwarebytes' Anti-Malware 1.44
    Version de la base de données: 3510
    Windows 6.0.6000
    Internet Explorer 7.0.6000.16643

    13/03/2010 10:13:29
    mbam-log-2010-03-13 (10-13-29).txt

    Type de recherche: Examen complet (C:\|)
    Eléments examinés: 299035
    Temps écoulé: 3 hour(s), 40 minute(s), 35 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 2
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Malwarebytes' Anti-Malware 1.44
    Version de la base de données: 3510
    Windows 6.0.6000
    Internet Explorer 7.0.6000.16643

    13/03/2010 17:05:55
    mbam-log-2010-03-13 (17-05-55).txt

    Type de recherche: Examen complet (C:\|)
    Eléments examinés: 299041
    Temps écoulé: 1 hour(s), 38 minute(s), 16 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    spybot
    --- Search result list ---
    Internet Explorer: [SBI $0BC7B918] User agent (Modification du Registre, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    MS Management Console: [SBI $ECD50EAD] Recent command list (1 fichiers) (Clé du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Microsoft Management Console\Recent File List

    MS Media Player: [SBI $3B9B7B9A] Last CD record path (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\MediaPlayer\Preferences\CDRecordPath

    MS Media Player: [SBI $67184AC2] Anonymous ID (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID

    MS Direct3D: [SBI $C2A44980] Most recent application (Modification du Registre, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name

    MS Direct3D: [SBI $C2A44980] Most recent application (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Direct3D\MostRecentApplication\Name

    MS Direct3D: [SBI $C2A44980] Most recent application (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name

    Real Jukebox 1.0: [SBI $578CA54D] Last Import wizard folder (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\RealNetworks\RealJukebox\1.0\Preferences\ImportWizardPath

    Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (2 fichiers) (Clé du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList

    Windows Explorer: [SBI $2026AFB6] User Assistant history IE (1 fichiers) (Clé du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count

    Windows Explorer: [SBI $6107D172] User Assistant history files (58 fichiers) (Clé du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count

    Windows Explorer: [SBI $D20DA0AD] Recent file global history (Clé du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

    Windows Media SDK: [SBI $37AAEDE6] Computer name (Modification du Registre, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

    Windows Media SDK: [SBI $37AAEDE6] Computer name (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

    Windows Media SDK: [SBI $37AAEDE6] Computer name (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

    Windows Media SDK: [SBI $CAA58B6E] Unique ID (Modification du Registre, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

    Windows Media SDK: [SBI $CAA58B6E] Unique ID (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

    Windows Media SDK: [SBI $CAA58B6E] Unique ID (Modification du Registre, nothing done)
    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

    Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Valeur du Registre, nothing done)
    HKEY_USERS\S-1-5-21-1797682213-4041698751-423991852-1000\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

    Cache: [SBI $49804B54] Cache (33) (Cache, nothing done)

    History: [SBI $49804B54] Historique (22) (Historique, nothing done)

    Félicitations!: Aucun mouchard n'a été trouvé. ()

    --- Spybot - Search & Destroy version: 1.5 (build: 20070830) ---

    2007-08-31 blindman.exe (1.0.0.6)
    2007-08-31 SDMain.exe (1.0.0.4)
    2007-08-31 SDUpdate.exe (1.0.6.4)
    2007-08-31 SDWinSec.exe (1.0.0.8)
    2007-08-31 SpybotSD.exe (1.5.1.15)
    2007-08-31 TeaTimer.exe (1.5.0.9)
    2007-09-11 unins000.exe (51.46.0.0)
    2007-08-31 Update.exe (1.4.0.5)
    2007-08-31 advcheck.dll (1.5.3.0)
    2007-04-02 aports.dll (2.1.0.0)
    2007-04-02 DelZip179.dll (1.79.5.3)
    2007-08-31 SDHelper.dll (1.5.0.8)
    2007-08-31 Tools.dll (2.1.2.0)
    2010-02-17 Includes\Adware.sbi (*)
    2010-03-09 Includes\AdwareC.sbi (*)
    2010-01-05 Includes\Beta.sbi (*)
    2007-11-06 Includes\Beta.uti (*)
    2010-01-25 Includes\Cookies.sbi (*)
    2009-11-03 Includes\Dialer.sbi (*)
    2010-03-09 Includes\DialerC.sbi (*)
    2010-01-25 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2010-03-09 Includes\HijackersC.sbi (*)
    2010-01-20 Includes\Keyloggers.sbi (*)
    2010-03-09 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2010-03-02 Includes\Malware.sbi (*)
    2010-03-09 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2010-03-02 Includes\PUPSC.sbi (*)
    2010-01-25 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2010-03-09 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2010-03-02 Includes\Spyware.sbi (*)
    2010-03-09 Includes\SpywareC.sbi (*)
    2010-03-08 Includes\Tracks.uti (*)
    2010-03-03 Includes\Trojans.sbi (*)
    2010-03-09 Includes\TrojansC-02.sbi (*)
    2010-03-09 Includes\TrojansC-03.sbi (*)
    2010-03-09 Includes\TrojansC-04.sbi (*)
    2010-03-09 Includes\TrojansC-05.sbi (*)
    2010-03-10 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2008-12-24 Plugins\TCPIPAddress.dll

    --- System information ---
    Windows Vista (Build: 6000) (6.0.6000)

    --- Startup entries list ---
    Located: HK_LM:Run, Adobe Reader Speed Launcher
    command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    size: 35696
    MD5: 452FA961163EF4AEE4815796A13AB2CF

    Located: HK_LM:Run, avast5
    command: C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    file: C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    size: 2756488
    MD5: 318270684C812E88FE63DC4C3021FC2B

    Located: HK_LM:Run, AVG8_TRAY
    command: C:\PROGRA~1\AVG\AVG8\avgtray.exe
    file: C:\PROGRA~1\AVG\AVG8\avgtray.exe
    size: 1950488
    MD5: 584B1250DC2C7EF9EFCBB5B61E815A75

    Located: HK_LM:Run, DXM6Patch_981116
    command: C:\Windows\p_981116.exe /Q:A
    file: C:\Windows\p_981116.exe
    size: 497376
    MD5: 8F2E2A9B5B4A433F43010C9B1AA8718C

    Located: HK_LM:Run, hpsysdrv
    command: c:\hp\support\hpsysdrv.exe
    file: c:\hp\support\hpsysdrv.exe
    size: 65536
    MD5: 85B8925F1A477DF7AEC93CABBEB04F1F

    Located: HK_LM:Run, KBD
    command: C:\HP\KBD\KbdStub.EXE
    file: C:\HP\KBD\KbdStub.EXE
    size: 65536
    MD5: 7088B136BB58A5F95CF0DE8386CA6C0F

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, NvMediaCenter
    command: RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, OsdMaestro
    command: "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    file: C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    size: 118784
    MD5: B1361669BDC6ED612C35B7C67ADA2240

    Located: HK_LM:Run, Symantec PIF AlertEng
    command: "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    file: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    size: 517768
    MD5: C837D17DE0B349539AA527EE750EBE2A

    Located: HK_LM:Run, vmtalk
    command: C:\Program Files\Common Files\Talkway\vmtalk.exe
    file: C:\Program Files\Common Files\Talkway\vmtalk.exe
    size: 61440
    MD5: 2EF94D5240D568760D6A83801A275712

    Located: HK_LM:Run, Windows Defender
    command: %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    file: C:\Program Files\Windows Defender\MSASCui.exe
    size: 1006264
    MD5: 9AD9E2FB2811123DA13DE84CC154AB77

    Located: HK_LM:Run, ZoneAlarm Client
    command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    size: 959976
    MD5: E8B180646BAE9E688D2E6D7EA8DED794

    Located: HK_LM:Run, (DISABLED)
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, Adobe Reader Speed Launcher (DISABLED)
    command: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, HP Software Update (DISABLED)
    command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    file: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    size: 49152
    MD5: B93C4070F24E46B0097648C276B5039E

    Located: HK_LM:Run, SunJavaUpdateSched (DISABLED)
    command: "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    file: C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    size: 144784
    MD5: 836DC47E6CAD975304D1D3EB2F516A1C

    Located: HK_LM:Run, TkBellExe (DISABLED)
    command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    size: 185896
    MD5: 1EDA1C63E0D2AE1AEBDF98083454079C

    Located: HK_LM:RunOnce, Launcher (DISABLED)
    command: %WINDIR%\SMINST\launcher.exe
    file: C:\Windows\SMINST\launcher.exe
    size: 44168
    MD5: 31539595F006DAE39F719735F30C3570

    Located: HK_CU:Run, msnmsgr
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    file: C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    size: 3883856
    MD5: 18B4B12358EFCF68D76812058A26181F

    Located: HK_CU:Run, Sidebar
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    file: C:\Program Files\Windows Sidebar\sidebar.exe
    size: 1232896
    MD5: 582F3A0BA61D8F0D50C66B592808B6D6

    Located: HK_CU:Run, SpybotSD TeaTimer
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 1460560
    MD5: B7D4586BFC0DD6C3BE7DCCC252A3E97E

    Located: HK_CU:Run, WMPNSCFG
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    size: 201728
    MD5: 20EF9002CFF89C4C1077E4415EC7297B

    Located: HK_CU:RunOnce, HPSoftwareUpdate
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Program Files\HP\HP Software Update\HPWUCli.exe
    file: C:\Program Files\HP\HP Software Update\HPWUCli.exe
    size: 633912
    MD5: D67448C5F32B67F9A6C1C32A6BA8ADF0

    Located: HK_CU:Run, (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, ehTray.exe (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Windows\ehome\ehTray.exe
    file: C:\Windows\ehome\ehTray.exe
    size: 125440
    MD5: 2E0953919779A44BF9DFB7B07C58535A

    Located: HK_CU:Run, MsnMsgr (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, Reminder (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: C:\Program Files\Microsoft Money\System\reminder.exe
    file: C:\Program Files\Microsoft Money\System\reminder.exe
    size: 37376
    MD5: A48BBC020DDB97B4F818815FD68C5443

    Located: HK_CU:Run, Skype (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    file: C:\Program Files\Skype\Phone\Skype.exe
    size: 20034600
    MD5: 4FD26740E9FF5C24D2BDF1EFC1425D23

    Located: HK_CU:Run, Steam (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: "c:\program files\steam\steam.exe" -silent
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, Veoh (DISABLED)
    where: S-1-5-21-1797682213-4041698751-423991852-1000...
    command: "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    file: C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    size: 3587120
    MD5: 48A00DB6BD3CDAE9ECB8827AC53E5BF8

    Located: Démarrage (tous utilisateurs), HP Digital Imaging Monitor.lnk (DISABLED)
    where: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup...
    command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    size: 210520
    MD5: 1BA45CDEF852381DA4A95D056DDB4B48

    --- Browser helper object list ---
    {02478D38-C3F9-4efb-9B51-7695ECA05670} (&Yahoo! Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: &Yahoo! Toolbar Helper
    description: Yahoo Companion!
    classification: Legitimate
    known filename: Ycomp*_*_*_*.dll
    info link: http://companion.yahoo.com/
    info source: TonyKlein
    Path: C:\Program Files\Yahoo!\Companion\Installs\cpn\
    Long name: yt.dll
    Short name:
    Date (created): 19/10/2007 22:56:50
    Date (last access): 22/02/2008 20:09:20
    Date (last write): 19/10/2007 22:56:50
    Filesize: 817936
    Attributes: archive
    MD5: A6D643A5F5B416FCC1C8049BBAF763BA
    CRC32: AC780D24
    Version: 2007.10.19.1

    {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: AcroIEHelperStub
    CLSID name: Adobe PDF Link Helper
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelperShim.dll
    Short name: ACROIE~2.DLL
    Date (created): 27/02/2009 11:07:26
    Date (last access): 04/05/2009 08:35:34
    Date (last write): 27/02/2009 11:07:26
    Filesize: 75128
    Attributes: archive
    MD5: 5CF6190CD875DA6B35256FEE573E7908
    CRC32: 764BA81B
    Version: 9.1.0.163

    {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: WormRadar.com IESiteBlocker.NavFilter
    CLSID name: AVG Safe Search
    Path: C:\Program Files\AVG\AVG8\
    Long name: avgssie.dll
    Short name:
    Date (created): 26/10/2008 09:57:52
    Date (last access): 09/02/2010 18:18:30
    Date (last write): 09/02/2010 18:18:30
    Filesize: 1164568
    Attributes: archive
    MD5: B646C9181EEF4847E249D0BC6F3C7064
    CRC32: 716A1087
    Version: 8.5.0.361

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 11/09/2007 18:03:38
    Date (last access): 11/09/2007 18:03:38
    Date (last write): 31/08/2007 15:46:14
    Filesize: 1122128
    Attributes: archive
    MD5: B8958471DAA4481E93B03DF8F991DD6E
    CRC32: 35E35F14
    Version: 1.5.0.8

    {5C255C8A-E604-49b4-9D64-90988571CECB} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live ID)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Programme d'aide de l'Assistant de connexion Windows Live ID
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 30/03/2009 15:31:54
    Date (last access): 18/10/2009 14:25:34
    Date (last write): 30/03/2009 15:31:54
    Filesize: 403824
    Attributes: archive
    MD5: 9144D1A2D7AC4CE489C863E11FC5E478
    CRC32: 55343708
    Version: 6.500.3146.0

    --- ActiveX list ---
    Microsoft XML Parser for Java (Microsoft XML Parser for Java)
    DPF name: Microsoft XML Parser for Java
    CLSID name:
    Installer:
    Codebase: file:///C:/Windows/Java/classes/xmldso.cab
    description:
    classification: Legitimate
    known filename: %WINDIR%\Java\classes\xmldso.cab
    info link:
    info source: Patrick M. Kolla

    {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control)
    DPF name:
    CLSID name: BDSCANONLINE Control
    Installer: C:\Windows\Downloaded Program Files\oscan8.inf
    Codebase: http://download.bitdefender.com/resources/scan8/oscan8.cab
    description:
    classification: Legitimate
    known filename: oscan8.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\DOWNLO~1\
    Long name: oscan82.ocx
    Short name:
    Date (created): 26/02/2008 14:59:18
    Date (last access): 26/02/2008 14:59:18
    Date (last write): 26/02/2008 14:59:18
    Filesize: 487424
    Attributes: archive
    MD5: 230A39D8950142CF2C94A5C1E567E95E
    CRC32: A546A5BB
    Version: 1.0.0.1

    {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
    DPF name:
    CLSID name: WUWebControl Class
    Installer: C:\Windows\Downloaded Program Files\wuweb.inf
    Codebase: http://update.microsoft.com/...
    description:
    classification: Legitimate
    known filename: wuweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\system32\
    Long name: wuweb.dll
    Short name:
    Date (created): 16/10/2008 13:12:24
    Date (last access): 16/10/2008 13:12:24
    Date (last write): 16/10/2008 13:12:24
    Filesize: 202776
    Attributes: archive
    MD5: 0006DE8037F5A562F96B461B3C557C3C
    CRC32: 9B107DED
    Version: 7.2.6001.788

    {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab)
    DPF name: System Requirements Lab
    CLSID name: System Requirements Lab Class
    Installer:
    Codebase: https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: sysreqlab2.dll
    Short name: SYSREQ~1.DLL
    Date (created): 29/03/2007 11:07:12
    Date (last access): 29/03/2007 11:07:12
    Date (last write): 29/03/2007 11:07:12
    Filesize: 206384
    Attributes: archive
    MD5: ED3B0F1BA60554B9D2E5AE1B02AD9306
    CRC32: E2F1D780
    Version: 2.30.0.0

    {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object)
    DPF name:
    CLSID name: DivXBrowserPlugin Object
    Installer: C:\Windows\Downloaded Program Files\DivXPlugin.inf
    Codebase: http://download.divx.com/player/DivXBrowserPlugin.cab
    description:
    classification: Legitimate
    known filename: npdivx32.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\DivX\DivX Web Player\
    Long name: npdivx32.dll
    Short name:
    Date (created): 12/05/2009 19:46:20
    Date (last access): 15/06/2009 20:09:24
    Date (last write): 12/05/2009 19:46:20
    Filesize: 1650992
    Attributes: archive
    MD5: 1DE714BB4BB48B10BC94FF84C9BC6471
    CRC32: 2CE80CCC
    Version: 1.5.0.52

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_05
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: npjpi160_05.dll
    Short name: NPJPI1~1.DLL
    Date (created): 22/02/2008 02:33:32
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 132496
    Attributes: archive
    MD5: 4FDFB86D78994BD71CBB779A7809E9CD
    CRC32: 5A0EB880
    Version: 6.0.50.13

    {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player)
    DPF name:
    CLSID name: Zylom Games Player
    Installer: C:\Windows\Downloaded Program Files\ZylomGamesPlayer.inf
    Codebase: http://game08.zylom.com/activex/zylomgamesplayer.cab
    description:
    classification: Legitimate
    known filename: zylomgamesplayer.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\Downloaded Program Files\
    Long name: zylomgamesplayer.dll
    Short name: ZYLOMG~1.DLL
    Date (created): 29/08/2006 13:17:22
    Date (last access): 29/08/2006 13:17:22
    Date (last write): 29/08/2006 13:17:22
    Filesize: 161976
    Attributes: archive
    MD5: 7FAF5222EEB546E1DC0F348DCB314B0B
    CRC32: B03D23B2
    Version: 2.0.0.1

    {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
    DPF name: Java Runtime Environment 1.4.2
    CLSID name: Java Plug-in 1.4.2
    Installer:
    Codebase: https://www.oracle.com/java/technologies/
    description:
    classification: Legitimate
    known filename: npjpi142.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_02
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi160_02.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_03
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_04
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_05
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 09/03/2008 17:57:58
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 509328
    Attributes: archive
    MD5: 5B42CB6A121256465B251840FDB1B2FE
    CRC32: 6EF0BCE9
    Version: 6.0.50.13

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_05
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_05\bin\
    Long name: npjpi160_05.dll
    Short name: NPJPI1~1.DLL
    Date (created): 22/02/2008 02:33:32
    Date (last access): 22/02/2008 02:33:32
    Date (last write): 22/02/2008 04:25:20
    Filesize: 132496
    Attributes: archive
    MD5: 4FDFB86D78994BD71CBB779A7809E9CD
    CRC32: 5A0EB880
    Version: 6.0.50.13

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\Windows\Downloaded Program Files\CONFLICT.1\swflash.inf
    Codebase: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\Windows\system32\Macromed\Flash\
    Long name: Flash10d.ocx
    Short name:
    Date (created): 03/11/2009 01:24:58
    Date (last access): 23/12/2009 18:25:40
    Date (last write): 03/11/2009 01:24:58
    Filesize: 3982240
    Attributes: readonly archive
    MD5: 3E5C5ED3EAEC55ABA27F68440360AE05
    CRC32: 761E8624
    Version: 10.0.42.34

    --- Process list ---
    PID: 756 ( 0) C:\Windows\system32\Dwm.exe
    size: 83456
    MD5: E87B968F3D49117445893EB0503FE34F
    PID: 116 ( 0) C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    size: 517768
    MD5: C837D17DE0B349539AA527EE750EBE2A
    PID: 1696 ( 0) C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    size: 959976
    MD5: E8B180646BAE9E688D2E6D7EA8DED794
    PID: 1304 ( 0) C:\hp\support\hpsysdrv.exe
    size: 65536
    MD5: 85B8925F1A477DF7AEC93CABBEB04F1F
    PID: 1344 ( 0) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    size: 118784
    MD5: B1361669BDC6ED612C35B7C67ADA2240
    PID: 1108 ( 0) C:\Windows\System32\rundll32.exe
    size: 44544
    MD5: 4B555106290BD117334E9A08761C035A
    PID: 2120 ( 0) C:\Program Files\Common Files\Talkway\vmtalk.exe
    size: 61440
    MD5: 2EF94D5240D568760D6A83801A275712
    PID: 2148 ( 0) C:\Windows\system32\taskeng.exe
    size: 166400
    MD5: 1226E9FAE5B8508801EC974E3C9D9C14
    PID: 2248 ( 0) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    size: 2756488
    MD5: 318270684C812E88FE63DC4C3021FC2B
    PID: 2304 ( 0) C:\Program Files\Windows Sidebar\sidebar.exe
    size: 1232896
    MD5: 582F3A0BA61D8F0D50C66B592808B6D6
    PID: 2432 ( 0) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 1460560
    MD5: B7D4586BFC0DD6C3BE7DCCC252A3E97E
    PID: 2452 ( 0) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    size: 3883856
    MD5: 18B4B12358EFCF68D76812058A26181F
    PID: 2524 ( 0) C:\Program Files\Windows Media Player\wmpnscfg.exe
    size: 201728
    MD5: 20EF9002CFF89C4C1077E4415EC7297B
    PID: 3532 ( 0) C:\hp\kbd\kbd.exe
    size: 61440
    MD5: C81BE1B951C36E97D3DA90DA745DA5F7
    PID: 2636 ( 0) C:\Program Files\Windows Live\Contacts\wlcomm.exe
    size: 27512
    MD5: 654480EA67078C7B4C6C8BA871B07D5D
    PID: 1800 ( 0) C:\Windows\system32\wuauclt.exe
    size: 53472
    MD5: 62BB79160F86CD962F312C68C6239BFD
    PID: 3580 ( 0) C:\Program Files\Microsoft Money\System\reminder.exe
    size: 37376
    MD5: A48BBC020DDB97B4F818815FD68C5443
    PID: 3824 ( 0) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 4943184
    MD5: C92780F50B8BB7A89E919585916494A9
    PID: 4580 ( 0) C:\Windows\explorer.exe
    size: 2923520
    MD5: 37440D09DEAE0B672A04DCCF7ABF06BE

    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 15/03/2010 07:34:36

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\@
    Download Directory
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\Windows\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    https://actus.sfr.fr
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    %SystemRoot%\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    https://home.sweetim.com/
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    https://www.01net.com/telecharger/
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 3: MSAFD Tcpip [TCP/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 4: MSAFD Tcpip [UDP/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 5: MSAFD Tcpip [RAW/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip [*]

    Protocol 6: Fournisseur de services RSVP TCPv6
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 7: Fournisseur de services RSVP TCP
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 8: Fournisseur de services RSVP UDPv6
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 9: Fournisseur de services RSVP UDP
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0624ECC3-94BF-4848-AB2B-CB28E61A9B21}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0624ECC3-94BF-4848-AB2B-CB28E61A9B21}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4AFFE183-C2C4-4C6B-9442-A9E3B4CA9DE4}] SEQPACKET 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4AFFE183-C2C4-4C6B-9442-A9E3B4CA9DE4}] DATAGRAM 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0624ECC3-94BF-4848-AB2B-CB28E61A9B21}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0624ECC3-94BF-4848-AB2B-CB28E61A9B21}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{4AFFE183-C2C4-4C6B-9442-A9E3B4CA9DE4}] SEQPACKET 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{4AFFE183-C2C4-4C6B-9442-A9E3B4CA9DE4}] DATAGRAM 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Espace de noms NLAv1 (Network Location Awareness Legacy)
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename:
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 1: TCP/IP
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename:
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 2: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 3: Fournisseur Shim d'affectation de noms de messagerie
    GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
    Filename:

    Namespace Provider 4: Fournisseur d'espace de noms du nuage PNRP
    GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:

    Namespace Provider 5: Fournisseur d'espace de noms du nom PNRP
    GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:07:36, on 13/03/2010
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Talkway\vmtalk.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\hp\kbd\kbd.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Microsoft Money\System\reminder.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = Download Directory
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\Windows\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [vmtalk] C:\Program Files\Common Files\Talkway\vmtalk.exe
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\RunOnce: [HPSoftwareUpdate] C:\Program Files\HP\HP Software Update\HPWUCli.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    0
  3. Redbart Messages postés 20952 Date d'inscription   Statut Membre Dernière intervention   3 382
     
    Bjr
    il suffit d'un antivirus + parefeu + antispyware

    je te conseille avira antivir + spybot +zonealarm tous gratuits

    supprime ceux qui sont en trop (nécessite souvent une aide sur le site - norton - avast-)

    supprime toutes les toolsbars :
    https://forums.cnetfrance.fr/tutoriels-securite-informatique/181457-toolbar-s-d-telecharger-et-utiliser

    mets à jour java et supprime les anciennes versions

    supprime les logiciels publicitaires :
    https://www.commentcamarche.net/telecharger/securite/2547-ad-remover/

    mais compte tenu de tes habitudes de jeu en ligne...

    ceci ne sont que des rustines, car tout est enregisté dans la BdR, il faudra balayer avec CCleaner
    supprimer les fichiers temporaires, les points de restauration

    commence a sauvegarder tes fichiers persos
    réfléchi à ce qui t'est vraiment utile et envisage une recovery
    0