Dialers détecté par Norton, supression ? - Page 2

  1. Contributeur sécurité
    oki
    les 010 ne jamais les fixer avec hijack et celle ci etais legitime
    0
    1. Oui je m'en suis rendue compte quand tu l'as dit, je suis allée vérifier... merci encore !
      0
  2. ok je vais laissé ewido faire le travail alors parce qu'à chaque fois que je lance bitdefender je me déconnecte de CCM et vice versa.
    Comme ça je garde le contact lol...

    Si autres instructions pendant ce temps pour soulager mémoire suis preneuse

    Merci à plus
    0
    1. Du coup j'ai pas relancé bitdefneder parce que je pense qu'il me fait perdre le contact avec toi. C pas grave hein ?....

      A plus
      0
      1. 0
        1. j'essaie de scan avec ce lien mais j'ai beau cliquer sur analyser maintenant, rien ne se passe.

          En plus bien que Messenger normalement supprimé j'ai des alertes de connexion de mes contacts.

          Lors de l'analyse ewido j'ai aussi vu passer des dossiers avg.

          J'attends le rapport de ewido et de norton et je te recontactes si tu es toujours là. c vrai que ça fait un moment qu'on est dessus. Tu as certainement aussi d'autres choses à faire....

          Encore merci
          0
      2. Oui oui je serai dans les parages ou demain matin...

        Mona
        0
        1. ça y est pour norton, il ne détecte plus le dialers mais a détecté le ad ware qu'il m'a proposer de supprimer et le mettre en quarataine
          1 élément détecté, 1 élément resolu, 0 élément restant, 1 élément en quarantaine.
          Est ce que je peux le supprimer définitivement, il est dans un logiciel publicitaire ?

          Pour ewido je suis à 66 %, 17 éléments infectés avec alertes à la détection et proposition de supprimer à chaque fois. A suivre...

          Comment se fait il que des programmes comme avg et messenger que j'ai supprimer dans ajout/suppression de programmes aient encore des fichiers actifs et non supprimables à cause de l'absence du lien programme ?

          Merci
          0
          1. Voici le rapport de ewido :

            ---------------------------------------------------------
            ewido security suite - Rapport de scan
            ---------------------------------------------------------

            + Créé le: 19:21:55, 30/10/2005
            + Somme de contrôle: DE5AE2C5

            + Résultats du scan:

            HKLM\SOFTWARE\Classes\CLSID\{28F00B04-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\CLSID\{28F00B20-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\CLSID\{28F00B21-DC4E-11d3-ABEC-005004A44EEB} -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.Configurator\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.Configurator.1\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.TransportCenter\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.TransportCenter.1\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.UserRegRequest\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKLM\SOFTWARE\Classes\Hiwire.UserRegRequest.1\CLSID\\ -> Spyware.HiWire : Nettoyer et sauvegarder
            HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Nettoyer et sauvegarder
            HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Nettoyer et sauvegarder
            HKU\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Nettoyer et sauvegarder
            HKU\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Spyware.ClientMan : Nettoyer et sauvegarder
            HKU\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Spyware.ClientMan : Nettoyer et sauvegarder
            HKU\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Spyware.ClientMan : Nettoyer et sauvegarder
            HKU\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Nettoyer et sauvegarder
            C:\WINDOWS\tmpcpyis.bat -> Backdoor.AcidShiver : Nettoyer et sauvegarder

            ::Fin du rapport
            0
            1. ça y est pour norton, il ne détecte plus le dialers mais a détecté le ad ware qu'il m'a proposer de supprimer

              Supprimer Ad-Aware, le logiciel que tu as téléchargé ??

              et le mettre en quarataine
              1 élément détecté, 1 élément resolu, 0 élément restant, 1 élément en quarantaine.
              Est ce que je peux le supprimer définitivement, il est dans un logiciel publicitaire ?


              Tout ce que Norton te détecte, il faut vider la quarantaine après.

              Pour ewido je suis à 66 %, 17 éléments infectés avec alertes à la détection et proposition de supprimer à chaque fois. A suivre...


              J'espère que tu acceptes la suppression ?

              Comment se fait il que des programmes comme avg et messenger que j'ai supprimer dans ajout/suppression de programmes aient encore des fichiers actifs et non supprimables à cause de l'absence du lien programme ?


              On s'en occupera dans HijackThis, ne t'inquiète pas !

              A+
              Mona
              0
              1. non c adware instantaccess que j'ai supprimer pas le logiciel téléchargé, ce virus était déjà là ce matin avec le dialer instantaccess avant que je fasse manip'

                oui j'ai accepté la suppression à chaque fois

                Je vais dans la quarantaine pour supprimer

                on avance c cool

                La marche à suivre c ?......
                0
                1. voici le journal de norton si ça peut servir :

                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :Analyse manuelle,Catégorie de risque : Logiciel publicitaire,Impact global du risque : Moyen,Performances : Moyen,Confidentialité : Faible,Suppression : Moyen,Furtif : Moyen,Action effectuée : Supprimé(s),Description :Zones affectées :
                  1 fichiers :
                  C:\WINDOWS\SYSTEM32\sysnetsvc32.dll - Effacé

                  61 clés de registre :
                  HKEY_USERS\S-1-5-19\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-20\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML - Aucune action requise
                  HKEY_USERS\.DEFAULT\Software\EGDHTML - Aucune action requise
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML - Aucune action requise
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML.1 - Aucune action requise
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary - Aucune action requise
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary.1 - Aucune action requise
                  HKEY_LOCAL_MACHINE\04 - Aucune action requise
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM - Aucune action requise
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM.1 - Aucune action requise
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH - Aucune action requise
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH.1 - Aucune action requise
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc.1 - Aucune action requise
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{6AA93DF6-6757-4338-9087-F7601DE18402} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{54C75FB0-6B8B-4278-BF7B-77036F15A69E} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{C6760A07-A574-4705-B113-7856315922C3} - Effacé
                  HKEY_CLASSES_ROOT\TypeLib\{F3A257E6-FA04-4B30-A1B6-6B89EB814544} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{C13FA88A-D264-4BC8-92ED-52EB8181E209} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{D7B59209-0ED9-4986-BD4A-527BE836C6B2} - Aucune action requise
                  HKEY_CLASSES_ROOT\TypeLib\{AD9B275B-E42D-4C7F-9FFB-29B5FB81688B} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{F8ACA5A0-060A-478A-8368-1407780D2251} - Aucune action requise
                  HKEY_USERS\S-1-5-19\Software\livesvc - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\livesvc - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\livesvc - Aucune action requise
                  HKEY_USERS\S-1-5-20\Software\livesvc - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\livesvc - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\livesvc - Effacé
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\livesvc - Aucune action requise
                  HKEY_USERS\.DEFAULT\Software\livesvc - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6} - Aucune action requise
                  HKEY_CLASSES_ROOT\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{50AD557E-3426-41FD-AFDD-2AF39BB1C387} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{0594AF7E-573B-40DF-8165-E47AB2EAEFE8} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{3947AC1D-DB09-4353-BBCC-55B97F5035EF} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{A58F3D09-4543-4396-8BE7-105F14DD6ED5} - Aucune action requise
                  HKEY_CLASSES_ROOT\TypeLib\{0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{1EB17D1C-141D-4D9D-91CB-24D99215851D} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{469C7080-8EC8-43A6-AD97-45848113743C} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{CEFB7B49-9652-464F-8AFD-A577C0500F39} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{2E30AC01-99D7-4E9C-B13E-94E1701B0AC9} - Aucune action requise
                  HKEY_CLASSES_ROOT\TypeLib\{E8C88115-4951-425B-8C45-4DFC5A5540EE} - Aucune action requise
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Effacé
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3} - Aucune action requise
                  HKEY_CLASSES_ROOT\CLSID\{CF5F84EB-D3FC-4F98-BE3B-F5B56B962CED} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{A7B323DA-0D0C-4298-8DE0-4F2AC4773284} - Aucune action requise
                  HKEY_CLASSES_ROOT\TypeLib\{06EC63CC-4823-4836-ABB8-AB5F3971FA5C} - Aucune action requise
                  HKEY_CLASSES_ROOT\Interface\{8F0A06F6-DF4D-4D54-B8CA-E8EEDBAE6DDB} - Aucune action requise

                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\sysnetsvc32.dll,Catégorie de risque : Logiciel publicitaire,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\sysnetsvc32.dll,Catégorie de risque : Logiciel publicitaire,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0467NAV~.TMP,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\System32\sysnetsvc32.dll,Catégorie de risque : Logiciel publicitaire,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\System32\sysnetsvc32.dll,Catégorie de risque : Logiciel publicitaire,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\PROGRAM FILES\NORTON INTERNET SECURITY\NORTON ANTIVIRUS\SAVRT\0467NAV~.TMP,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :Analyse manuelle,Catégorie de risque : Numéroteur,Impact global du risque : Elevé,Performances : Elevé,Confidentialité : Elevé,Suppression : Elevé,Furtif : Elevé,Action effectuée : Echec de la suppression,Description :Zones affectées :
                  9 fichiers :
                  \\.\C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0466NAV~.TMP - Echec de l'effacement
                  C:\Documents and Settings\All Users\Bureau\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\All Users\Bureau\Instant Access.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\Instant Access.lnk - Aucune action effectuée
                  C:\dfuck.ico - Aucune action effectuée
                  C:\Video Party.ico - Aucune action effectuée
                  C:\WINDOWS\system32\mseggrpid.dll - Aucune action effectuée
                  C:\WINDOWS\tmlpcert2005 - Aucune action effectuée

                  1 processus :
                  C:\WINDOWS\system32\rundll32.exe - Aucune action requise

                  80 clés de registre :
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC9677B-8006-4336-9D49-2C797AEFCB9E} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1604DF98-D1A5-44FE-844A-98D6FD0518D0} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF4DCD99-D26B-44A4-BA77-CFDCC97E7291} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94742E3F-D9A1-4780-9A87-2FFA43655DA2} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML.1 - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial.1 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\LoginUsed - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DateR - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DataD - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\OutsideDigit - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable - Aucune action effectuée

                  2 fichiers INI :
                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk - Aucune action effectuée
                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk - Aucune action effectuée

                  Source :Analyse manuelle,Catégorie de risque : Logiciel publicitaire,Impact global du risque : Moyen,Performances : Moyen,Confidentialité : Faible,Suppression : Moyen,Furtif : Moyen,Action effectuée : Détecté,Description :Zones potentiellement affectées :
                  1 fichiers :
                  C:\WINDOWS\SYSTEM32\sysnetsvc32.dll

                  61 clés de registre :
                  HKEY_USERS\S-1-5-19\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML
                  HKEY_USERS\S-1-5-20\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML
                  HKEY_USERS\.DEFAULT\Software\EGDHTML
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML.1
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary.1
                  HKEY_LOCAL_MACHINE\04
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM.1
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH.1
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc.1
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc
                  HKEY_CLASSES_ROOT\CLSID\{6AA93DF6-6757-4338-9087-F7601DE18402}
                  HKEY_CLASSES_ROOT\CLSID\{54C75FB0-6B8B-4278-BF7B-77036F15A69E}
                  HKEY_CLASSES_ROOT\CLSID\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_CLASSES_ROOT\TypeLib\{F3A257E6-FA04-4B30-A1B6-6B89EB814544}
                  HKEY_CLASSES_ROOT\Interface\{C13FA88A-D264-4BC8-92ED-52EB8181E209}
                  HKEY_CLASSES_ROOT\CLSID\{D7B59209-0ED9-4986-BD4A-527BE836C6B2}
                  HKEY_CLASSES_ROOT\TypeLib\{AD9B275B-E42D-4C7F-9FFB-29B5FB81688B}
                  HKEY_CLASSES_ROOT\Interface\{F8ACA5A0-060A-478A-8368-1407780D2251}
                  HKEY_USERS\S-1-5-19\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\livesvc
                  HKEY_USERS\S-1-5-20\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\livesvc
                  HKEY_USERS\.DEFAULT\Software\livesvc
                  HKEY_CLASSES_ROOT\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45}
                  HKEY_CLASSES_ROOT\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6}
                  HKEY_CLASSES_ROOT\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53}
                  HKEY_CLASSES_ROOT\CLSID\{50AD557E-3426-41FD-AFDD-2AF39BB1C387}
                  HKEY_CLASSES_ROOT\CLSID\{0594AF7E-573B-40DF-8165-E47AB2EAEFE8}
                  HKEY_CLASSES_ROOT\Interface\{3947AC1D-DB09-4353-BBCC-55B97F5035EF}
                  HKEY_CLASSES_ROOT\Interface\{A58F3D09-4543-4396-8BE7-105F14DD6ED5}
                  HKEY_CLASSES_ROOT\TypeLib\{0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C}
                  HKEY_CLASSES_ROOT\CLSID\{EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1}
                  HKEY_CLASSES_ROOT\CLSID\{1EB17D1C-141D-4D9D-91CB-24D99215851D}
                  HKEY_CLASSES_ROOT\CLSID\{469C7080-8EC8-43A6-AD97-45848113743C}
                  HKEY_CLASSES_ROOT\CLSID\{CEFB7B49-9652-464F-8AFD-A577C0500F39}
                  HKEY_CLASSES_ROOT\Interface\{2E30AC01-99D7-4E9C-B13E-94E1701B0AC9}
                  HKEY_CLASSES_ROOT\TypeLib\{E8C88115-4951-425B-8C45-4DFC5A5540EE}
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_CLASSES_ROOT\CLSID\{CF5F84EB-D3FC-4F98-BE3B-F5B56B962CED}
                  HKEY_CLASSES_ROOT\Interface\{A7B323DA-0D0C-4298-8DE0-4F2AC4773284}
                  HKEY_CLASSES_ROOT\TypeLib\{06EC63CC-4823-4836-ABB8-AB5F3971FA5C}
                  HKEY_CLASSES_ROOT\Interface\{8F0A06F6-DF4D-4D54-B8CA-E8EEDBAE6DDB}

                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :Analyse manuelle,Catégorie de risque : Numéroteur,Impact global du risque : Elevé,Performances : Elevé,Confidentialité : Elevé,Suppression : Elevé,Furtif : Elevé,Action effectuée : Echec de la suppression,Description :Zones affectées :
                  9 fichiers :
                  \\.\C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0466NAV~.TMP - Echec de l'effacement
                  C:\Documents and Settings\All Users\Bureau\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\All Users\Bureau\Instant Access.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\Instant Access.lnk - Aucune action effectuée
                  C:\dfuck.ico - Aucune action effectuée
                  C:\Video Party.ico - Aucune action effectuée
                  C:\WINDOWS\system32\mseggrpid.dll - Aucune action effectuée
                  C:\WINDOWS\tmlpcert2005 - Aucune action effectuée

                  1 processus :
                  C:\WINDOWS\system32\rundll32.exe - Aucune action requise

                  80 clés de registre :
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC9677B-8006-4336-9D49-2C797AEFCB9E} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1604DF98-D1A5-44FE-844A-98D6FD0518D0} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF4DCD99-D26B-44A4-BA77-CFDCC97E7291} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94742E3F-D9A1-4780-9A87-2FFA43655DA2} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML.1 - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial.1 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\LoginUsed - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DateR - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DataD - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\OutsideDigit - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable - Aucune action effectuée

                  2 fichiers INI :
                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk - Aucune action effectuée
                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk - Aucune action effectuée

                  Source :Analyse manuelle,Catégorie de risque : Logiciel publicitaire,Impact global du risque : Moyen,Performances : Moyen,Confidentialité : Faible,Suppression : Moyen,Furtif : Moyen,Action effectuée : Détecté,Description :Zones potentiellement affectées :
                  1 fichiers :
                  C:\WINDOWS\SYSTEM32\sysnetsvc32.dll

                  61 clés de registre :
                  HKEY_USERS\S-1-5-19\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML
                  HKEY_USERS\S-1-5-20\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML
                  HKEY_USERS\.DEFAULT\Software\EGDHTML
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML
                  HKEY_CLASSES_ROOT\EGDHTML.EGDialHTML.1
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary
                  HKEY_CLASSES_ROOT\EGCOMLIB.EGComLibrary.1
                  HKEY_LOCAL_MACHINE\04
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM
                  HKEY_CLASSES_ROOT\P2ECOM.EGP2ECOM.1
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH
                  HKEY_CLASSES_ROOT\EGAUTH.EGEGAUTH.1
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc.1
                  HKEY_CLASSES_ROOT\EGCOMSERVICE.EGComSvc
                  HKEY_CLASSES_ROOT\CLSID\{6AA93DF6-6757-4338-9087-F7601DE18402}
                  HKEY_CLASSES_ROOT\CLSID\{54C75FB0-6B8B-4278-BF7B-77036F15A69E}
                  HKEY_CLASSES_ROOT\CLSID\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_CLASSES_ROOT\TypeLib\{F3A257E6-FA04-4B30-A1B6-6B89EB814544}
                  HKEY_CLASSES_ROOT\Interface\{C13FA88A-D264-4BC8-92ED-52EB8181E209}
                  HKEY_CLASSES_ROOT\CLSID\{D7B59209-0ED9-4986-BD4A-527BE836C6B2}
                  HKEY_CLASSES_ROOT\TypeLib\{AD9B275B-E42D-4C7F-9FFB-29B5FB81688B}
                  HKEY_CLASSES_ROOT\Interface\{F8ACA5A0-060A-478A-8368-1407780D2251}
                  HKEY_USERS\S-1-5-19\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\livesvc
                  HKEY_USERS\S-1-5-20\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\livesvc
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\livesvc
                  HKEY_USERS\.DEFAULT\Software\livesvc
                  HKEY_CLASSES_ROOT\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45}
                  HKEY_CLASSES_ROOT\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6}
                  HKEY_CLASSES_ROOT\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53}
                  HKEY_CLASSES_ROOT\CLSID\{50AD557E-3426-41FD-AFDD-2AF39BB1C387}
                  HKEY_CLASSES_ROOT\CLSID\{0594AF7E-573B-40DF-8165-E47AB2EAEFE8}
                  HKEY_CLASSES_ROOT\Interface\{3947AC1D-DB09-4353-BBCC-55B97F5035EF}
                  HKEY_CLASSES_ROOT\Interface\{A58F3D09-4543-4396-8BE7-105F14DD6ED5}
                  HKEY_CLASSES_ROOT\TypeLib\{0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C}
                  HKEY_CLASSES_ROOT\CLSID\{EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1}
                  HKEY_CLASSES_ROOT\CLSID\{1EB17D1C-141D-4D9D-91CB-24D99215851D}
                  HKEY_CLASSES_ROOT\CLSID\{469C7080-8EC8-43A6-AD97-45848113743C}
                  HKEY_CLASSES_ROOT\CLSID\{CEFB7B49-9652-464F-8AFD-A577C0500F39}
                  HKEY_CLASSES_ROOT\Interface\{2E30AC01-99D7-4E9C-B13E-94E1701B0AC9}
                  HKEY_CLASSES_ROOT\TypeLib\{E8C88115-4951-425B-8C45-4DFC5A5540EE}
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6760A07-A574-4705-B113-7856315922C3}
                  HKEY_CLASSES_ROOT\CLSID\{CF5F84EB-D3FC-4F98-BE3B-F5B56B962CED}
                  HKEY_CLASSES_ROOT\Interface\{A7B323DA-0D0C-4298-8DE0-4F2AC4773284}
                  HKEY_CLASSES_ROOT\TypeLib\{06EC63CC-4823-4836-ABB8-AB5F3971FA5C}
                  HKEY_CLASSES_ROOT\Interface\{8F0A06F6-DF4D-4D54-B8CA-E8EEDBAE6DDB}

                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\PROGRAM FILES\NORTON INTERNET SECURITY\NORTON ANTIVIRUS\SAVRT\0466NAV~.TMP,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\PROGRAM FILES\NORTON INTERNET SECURITY\NORTON ANTIVIRUS\SAVRT\0466NAV~.TMP,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\SYSTEM32\MSCLOCK32.DLL,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :C:\WINDOWS\system32\msclock32.dll,Catégorie de risque : Numéroteur,Action effectuée : Détecté
                  Source :Analyse manuelle,Catégorie de risque : Numéroteur,Impact global du risque : Elevé,Performances : Elevé,Confidentialité : Elevé,Suppression : Elevé,Furtif : Elevé,Action effectuée : Echec de la suppression,Description :Zones affectées :
                  9 fichiers :
                  \\.\C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0466NAV~.TMP - Echec de l'effacement
                  C:\Documents and Settings\All Users\Bureau\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\All Users\Bureau\Instant Access.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\FunFunFun.lnk - Aucune action effectuée
                  C:\Documents and Settings\mangin geraldine\Menu Démarrer\Instant Access.lnk - Aucune action effectuée
                  C:\dfuck.ico - Aucune action effectuée
                  C:\Video Party.ico - Aucune action effectuée
                  C:\WINDOWS\system32\mseggrpid.dll - Aucune action effectuée
                  C:\WINDOWS\tmlpcert2005 - Aucune action effectuée

                  1 processus :
                  C:\WINDOWS\system32\rundll32.exe - Aucune action requise

                  80 clés de registre :
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC9677B-8006-4336-9D49-2C797AEFCB9E} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1604DF98-D1A5-44FE-844A-98D6FD0518D0} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF4DCD99-D26B-44A4-BA77-CFDCC97E7291} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94742E3F-D9A1-4780-9A87-2FFA43655DA2} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53} - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDHTML.EGDialHTML.1 - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EGDialObject.EGDial.1 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BD8400524261DF1ADBD8860F22C9CE2B97471448 - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\EGDHTML - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\Instant Access - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\goicfboogidikkejccmclpieicihhlpo bgdjdn - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\access-to - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\LoginUsed - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DateR - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\DataD - Aucune action effectuée
                  HKEY_LOCAL_MACHINE\OutsideDigit - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\minidialer - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1008\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0\ppcimdnnnjbeahepfabjipfginloedkg kogbai - Aucune action effectuée
                  HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer - Aucune action effectuée
                  HKEY_USERS\S-1-5-21-2000478354-789336058-854245398-1007\
                  0
                  1. Bien !

                    Nous allons passer à l'étape suivante.

                    Met moi ici un log HT et n'oublie pas de faire avant ce que je t'ai demandé au post <8>.

                    A+
                    Mona
                    0
                    1. je récapitule le 8 pour voir si bien compris

                      J'ai créé un dossier ou j'ai enregistré l'application HT (et le fichier archive winrar). je lance l'application, clique sur scan and log.....
                      attends que ça se passe .
                      Ca ouvre un document bloc note que je conserve dans le c:\hjt créé

                      Je ne ferme aucun des documents créés par HT application

                      C bien ça ?
                      0
                  2. Voici mon log HT. J'espère avoir fait bonnes manip'

                    Logfile of HijackThis v1.99.1
                    Scan saved at 19:57:12, on 30/10/2005
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Norton Internet Security\ISSVC.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\drivers\KodakCCS.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\WINDOWS\system32\pctspk.exe
                    C:\WINDOWS\System32\ScsiAccess.EXE
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Program Files\Microsoft Works\WksSb.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\LCPA Lite\Lcpa Lite.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
                    C:\Program Files\Hewlett-Packard\hp psc 700 series\FRU\Remind32.exe
                    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                    C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
                    C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
                    C:\Program Files\palmOne\HOTSYNC.EXE
                    C:\PROGRA~1\HEWLET~1\HPPSC7~1\BIN\HPOEVM07.EXE
                    C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\HPOSTS07.exe
                    C:\WINDOWS\system32\hpoipm07.exe
                    C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\hjt\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr2.hpwis.com/
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr2.hpwis.com/
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr2.hpwis.com/
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr2.hpwis.com/
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
                    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
                    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                    O4 - HKLM\..\Run: [LcpaLite] "C:\Program Files\LCPA Lite\Lcpa Lite.exe"
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
                    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
                    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
                    O4 - Startup: PowerReg Scheduler.exe
                    O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
                    O4 - Global Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\FRU\Remind32.exe
                    O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                    O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
                    O4 - Global Startup: Picture Package VCD Maker.lnk = ?
                    O4 - Global Startup: Picture Package Menu.lnk = ?
                    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
                    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
                    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
                    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
                    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
                    O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
                    O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_FR_XP.cab
                    O16 - DPF: {BE5A7132-329F-4319-B781-2A83BFE51534} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1045_FR_XP.cab
                    O16 - DPF: {D8B94E9A-A34B-4253-BF48-C7CB7F2CFDB0} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1046_FR_XP.cab
                    O18 - Filter: text/html - {C6F62B7A-5450-4A2F-8687-6CEEC3AEB055} - C:\WINDOWS\system32\controlkids2.dll
                    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
                    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    0
                    1. Bonjour !

                      Imprime ceci pour ne rien oublier de faire :

                      Méthode à suivre dans l'ordre...

                      ----------------------------------------------------------------------------
                      Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5)
                      ----------------------------------------------------------------------------
                      Désactive ta restauration système :
                      Clic droit sur poste de travail puis,
                      propriété, tu cliques sur onglet restauration système
                      tu coches la case « désactiver la restauration » et applique
                      ----------------------------------------------------------------------------
                      Affiche tous les fichiers et dossiers :
                      Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                      Coche « afficher les fichiers et dossiers cachés »

                      Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                      Décoche « masquer les extensions dont le type est connu »
                      Puis fais «Ok» pour valider les changements.

                      Et appliquer !
                      ----------------------------------------------------------------------------
                      Vide tes fichiers temps et tempory internet file avec CleanUp
                      ----------------------------------------------------------------------------
                      Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr2.hpwis.com/
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr2.hpwis.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr2.hpwis.com/
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr2.hpwis.com/
                      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                      O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                      O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
                      O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_FR_XP.cab
                      O16 - DPF: {BE5A7132-329F-4319-B781-2A83BFE51534} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1045_FR_XP.cab
                      O16 - DPF: {D8B94E9A-A34B-4253-BF48-C7CB7F2CFDB0} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1046_FR_XP.cab
                      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
                      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)

                      ----------------------------------------------------------------------------
                      Recherche et supprime ceci:

                      C:\PROGRA~1\Grisoft\ => le dossier

                      ----------------------------------------------------------------------------
                      Arrête ces services :

                      Clique sur Démarrer->exécuter->tape: services.msc

                      Double-clique:
                      Service: AVG7 Alert Manager Server (Avg7Alrt)
                      Service: AVG7 Update Service (Avg7UpdSvc)

                      Règle-les sur "Arrêté" et "Désactivé".
                      ----------------------------------------------------------------------------
                      Passe Ad-Aware et vire tout ce qu’il trouve + vide la quarantaine (et j’espère qu’il ne va pas bloquer !)
                      ----------------------------------------------------------------------------
                      Passe Spybot et vire tout ce qu’il trouve + vide la quarantaine
                      ----------------------------------------------------------------------------
                      > Tu vides ta poubelle et tu redémarres en mode normal et refais un HijackThis que tu postes ici.

                      Nous sommes maintenant débarrassées de AVG !
                      Et je n’ai pas trouvé de traces de messenger plus, mais de msn messenger, ce qui est bien !

                      A+
                      Mona
                      0
                      1. Re Salut

                        Excuse Mona, pb de connexion en plus de tout ça....aie aie aie
                        Maintenant que c réglé et que j'ai suivi tes instructions, je te donne le log hijackthis qui en ressort.

                        Merci

                        Logfile of HijackThis v1.99.1
                        Scan saved at 21:19:01, on 07/11/2005
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Norton Internet Security\ISSVC.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\ewido\security suite\ewidoctrl.exe
                        C:\WINDOWS\system32\drivers\KodakCCS.exe
                        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        C:\WINDOWS\system32\pctspk.exe
                        C:\WINDOWS\System32\ScsiAccess.EXE
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\hjt\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                        O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
                        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
                        O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
                        O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
                        O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
                        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Reference 2001\EROProj.dll
                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
                        O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                        O18 - Filter: text/html - {C6F62B7A-5450-4A2F-8687-6CEEC3AEB055} - C:\WINDOWS\system32\controlkids2.dll
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                        O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
                        O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                        O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

                        c impressionnant quand même de savoir déchiffrer tout ça encore bravo !!!
                        0
                        1. Bonsoir lou,

                          Je tombe peut-être comme un cheveu dans la soupe dans cette conversation mais je voulais simplement donner mon avis. Pour ma part, je suis utilisateur de Norton Internet Security depuis 5 ans et j'en suis très satisfait. Je constate effectivement que beaucoup de gens semblent s'en plaindre mais peut-être s'agit-il d'un problème d'utilisation et de configuration.
                          Lorsque tu l'as fait fonctionner, pourquoi n'as tu pas demandé la suppression des fichiers détectés ?
                          A ce stade, je ne voudrais pas t'embrouiller dans les démarches que tu es occupée à faire avec mona et il vaut donc mieux continuer. Concernant la suppression de NIS, la désintallation manuelle (hors ajout/suppression de programmes) est très difficile et engendre systématiquement des problèmes car il faut absolument que TOUS les fichiers du programmes soient désinstallés. Je t'invite donc à lire la page suivante :

                          http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/4f60eedf1156c8068525695b005ca288/1168d30686f6fdb080256fe3003757be?OpenDocument

                          Cette page te permettra, entre autres, de télécharger le fichier SymNRT qui te permettra de désintaller NIS.

                          D'autre part, tu parles d'un pc très lent au démarrage. As-tu, dans un premier temps, tout simplement effectué une défragmentation du disque dur ?
                          As-tu utilisé un logiciel de résolution de problèmes comme Norton Utilities par exemples ? Il est vrai que ce dernier est payant mais tu peux éventuellement télécharger tuneup utilities (voir la page : http://www.01net.com/telecharger/windows/Utilitaire/optimiseurs_et_tests/fiches/26913.html) qui est un shareware en français. Ce genre de logiciel te permettrait déjà de solutionner pas mal de problèmes.

                          Bon courage
                          0
                          Précédent
                          • 1
                          • 2