A voir également:
- Check this out lol NEW MSN 11 PLUS!
- Fixwin 11 - Télécharger - Divers Utilitaires
- Logiciel montage vidéo gratuit windows 11 - Guide
- Windows 11 - Accueil - Windows
- Compatibilite windows 11 - Guide
- Microsoft money windows 11 - Télécharger - Comptabilité & Facturation
49 réponses
salut
ne plus se connecter a msn, c est surrement un ver
Dis lui de faire ca
télécharge HijackThis ici:
http://www.hijackthis.de/downloads/hijackthis_199.zip
Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Lance le puis:
clique sur "do a system scan and save logfile" (cf démo)
faire un copier coller du log entier sur le forum
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Bon courage
A+
ne plus se connecter a msn, c est surrement un ver
Dis lui de faire ca
télécharge HijackThis ici:
http://www.hijackthis.de/downloads/hijackthis_199.zip
Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Lance le puis:
clique sur "do a system scan and save logfile" (cf démo)
faire un copier coller du log entier sur le forum
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Bon courage
A+
salut
le log est incomplet, merci de tout mettre
voir video
et fais ceci egalement:
Télécharge lopxp ici:
http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)
2) dezippe le (clic droit dessus > extraire tout)
et lance lopxp.bat
le bloc note va s'ouvrir, copie et colle le contenu ici
A+
le log est incomplet, merci de tout mettre
voir video
et fais ceci egalement:
Télécharge lopxp ici:
http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)
2) dezippe le (clic droit dessus > extraire tout)
et lance lopxp.bat
le bloc note va s'ouvrir, copie et colle le contenu ici
A+
bonjour Je prends la suite de mon fils.
Le virus est toujours la!!! et c'est tres difficile.
Pourriez-vous reprendre l'aide en ligne SVP
Rapport lopxp + un hijackthis
Rapport fait à 10:28:47,30 le 26/12/2005
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 116883279872 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
15/01/2005 17:49 <REP> Skype
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 32208 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> .
2 fichier(s) 32270 octets
26 R‚p(s) 116883271680 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
20/04/2005 21:31 574 Norton AntiVirus - Analyser mon ordinateur.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
5 fichier(s) 1ÿ291 octets
2 R‚p(s) 116ÿ883ÿ271ÿ680 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
Logfile of HijackThis v1.99.1
Scan saved at 10:43:50, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Winamp\winampa.exe
C:\Msmsgsis.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\DrvMon.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\program files\steam\steam.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.000\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMRNaz5s9cz16Vk2Jp6jlHqzdAG.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dlzikxvudzsfvxe.us/ZfynToormX_6f1m2fgpPcF3B3KXpCNWJYnIoBSAaodg.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5A56E72-EA2D-41FD-8D60-3EECC3E1CAC6}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
Le virus est toujours la!!! et c'est tres difficile.
Pourriez-vous reprendre l'aide en ligne SVP
Rapport lopxp + un hijackthis
Rapport fait à 10:28:47,30 le 26/12/2005
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 116883279872 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 116883275776 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
15/01/2005 17:49 <REP> Skype
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 32208 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> .
2 fichier(s) 32270 octets
26 R‚p(s) 116883271680 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
20/04/2005 21:31 574 Norton AntiVirus - Analyser mon ordinateur.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
5 fichier(s) 1ÿ291 octets
2 R‚p(s) 116ÿ883ÿ271ÿ680 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
Logfile of HijackThis v1.99.1
Scan saved at 10:43:50, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Winamp\winampa.exe
C:\Msmsgsis.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\DrvMon.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\program files\steam\steam.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.000\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMRNaz5s9cz16Vk2Jp6jlHqzdAG.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dlzikxvudzsfvxe.us/ZfynToormX_6f1m2fgpPcF3B3KXpCNWJYnIoBSAaodg.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5A56E72-EA2D-41FD-8D60-3EECC3E1CAC6}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
SVP Ne me laissez pas tomber je suis si fragile......
Sans rire apportez moi vos lumières; J'ai déja eu l'occasion de tester vos compétences et je les ai fortement apprécier. Merci par avance.
Sans rire apportez moi vos lumières; J'ai déja eu l'occasion de tester vos compétences et je les ai fortement apprécier. Merci par avance.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonjour Enouie !!!
Commencez par faire un peu de ménage.
L'ordinateur de votre fils est très infecté.
Pour commencer, téléchargez CleanUp! :
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
Lancez le programme, cliquez sur CleanUp et patientez.
Si une fenêtre s'affiche vous demandant de redémarrer, acceptez.
Ensuite, il y'a 2 antivirus, Norton et AVG.
Supprimez-en un.
Si vous avez A² Free, mettez-le à jour et lancez un scan.
Copiez-collez le rapport ici, svp.
Tenez-nous au courant !!! :-)
A++++++++
Commencez par faire un peu de ménage.
L'ordinateur de votre fils est très infecté.
Pour commencer, téléchargez CleanUp! :
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
Lancez le programme, cliquez sur CleanUp et patientez.
Si une fenêtre s'affiche vous demandant de redémarrer, acceptez.
Ensuite, il y'a 2 antivirus, Norton et AVG.
Supprimez-en un.
Si vous avez A² Free, mettez-le à jour et lancez un scan.
Copiez-collez le rapport ici, svp.
Tenez-nous au courant !!! :-)
A++++++++
merci pour votre reponse. Plus rien ne fonctionne correctement; pas moyen de demarer en mode sans echec, d'ouvrir ajout ou suppression de programe. Je suis longue mais je fait ce que je peux.CleanUp! started on 12/26/05 14:03:09.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\WDIVK5QR\xpt[1].css - deleted
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\MSHist012005122620051227\index.dat - deleted
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\MSHist012005122620051227\ - deleted
'Typed URLs' (Internet Explorer) - removed from the registry.
Visited: guillaume@https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=payments@stevengould.org&item_name=CleanUp!&no_shipping=1&amount= - deleted
C:\Documents and Settings\guillaume\Cookies\guillaume@paypal[2].txt - deleted
C:\Documents and Settings\guillaume\Cookies\guillaume@www.paypal[1].txt - deleted
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
Cookie:guillaume@www.paypal.com/ - deleted
Cookie:guillaume@paypal.com/ - deleted
Cookie:guillaume@lop.com/ - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\locals~1\tempor~1\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\CNMSM61.EXE-0A018AF6.pf - deleted
C:\WINDOWS\Prefetch\WINHLP32.EXE-2C18E975.pf - deleted
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! 4.0 recovered 132.6 KB of disk space from 10 files.
CleanUp! finished on 12/26/05 14:05:52.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\WDIVK5QR\xpt[1].css - deleted
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\MSHist012005122620051227\index.dat - deleted
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\MSHist012005122620051227\ - deleted
'Typed URLs' (Internet Explorer) - removed from the registry.
Visited: guillaume@https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=payments@stevengould.org&item_name=CleanUp!&no_shipping=1&amount= - deleted
C:\Documents and Settings\guillaume\Cookies\guillaume@paypal[2].txt - deleted
C:\Documents and Settings\guillaume\Cookies\guillaume@www.paypal[1].txt - deleted
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
Cookie:guillaume@www.paypal.com/ - deleted
Cookie:guillaume@paypal.com/ - deleted
Cookie:guillaume@lop.com/ - deleted
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\locals~1\tempor~1\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\RN13J5CS\index[2].php currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\Prefetch\CNMSM61.EXE-0A018AF6.pf - deleted
C:\WINDOWS\Prefetch\WINHLP32.EXE-2C18E975.pf - deleted
C:\Documents and Settings\guillaume\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\guillaume\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! 4.0 recovered 132.6 KB of disk space from 10 files.
CleanUp! finished on 12/26/05 14:05:52.
a² Report
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
a² Report
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
a² Report
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
voila le resultat
Nom du fichier Diagnostic
C:\Documents and Settings\guillaume\Bureau\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\Documents and Settings\guillaume\Cookies\guillaume@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Cookies\guillaume@lop[1].txt Trace.TrackingCookie
C:\Documents and Settings\guillaume\Mes documents\Smit\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
salut
du calme !!
Ce qui te detecte, tu n y touche pas !!!!!! Il sont bons, rien a craindre
ou en sont tes soucis? remet un hijack this
a+
du calme !!
Ce qui te detecte, tu n y touche pas !!!!!! Il sont bons, rien a craindre
ou en sont tes soucis? remet un hijack this
a+
Bonjour
voila
Logfile of HijackThis v1.99.1
Scan saved at 17:57:25, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\Msmsgsis.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\DrvMon.exe
C:\program files\steam\steam.exe
C:\Program Files\a-squared\a2guard.exe
c:\progra~1\intern~1\iexplore.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMRNaz5s9cz16Vk2Jp6jlHqzdAG.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5A56E72-EA2D-41FD-8D60-3EECC3E1CAC6}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
voila
Logfile of HijackThis v1.99.1
Scan saved at 17:57:25, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\Msmsgsis.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\DrvMon.exe
C:\program files\steam\steam.exe
C:\Program Files\a-squared\a2guard.exe
c:\progra~1\intern~1\iexplore.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMRNaz5s9cz16Vk2Jp6jlHqzdAG.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5A56E72-EA2D-41FD-8D60-3EECC3E1CAC6}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
check this out :P lol NEW MSN 11 PLUS! http://msn11plus.shizero.com !
ok,
Télécharge lopxp ici:
http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)
2) dezippe le (clic droit dessus > extraire tout)
et lance lopxp.bat
le bloc note va s'ouvrir, copie et colle le contenu ici
A+
Télécharge lopxp ici:
http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)
2) dezippe le (clic droit dessus > extraire tout)
et lance lopxp.bat
le bloc note va s'ouvrir, copie et colle le contenu ici
A+
Rapport fait à 18:20:32,03 le 26/12/2005
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298562560 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI.000\Application Data
26/12/2005 12:56 <REP> AVG7
26/12/2005 12:49 62 desktop.ini
26/12/2005 12:49 <REP> ..
26/12/2005 12:49 <REP> Microsoft
26/12/2005 12:49 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
26/12/2005 17:31 <REP> Webroot
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 34952 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> .
2 fichier(s) 35014 octets
26 R‚p(s) 118298554368 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
26/12/2005 17:32 820 wrSpySweeperTrialSweep.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .
5 fichier(s) 1ÿ537 octets
2 R‚p(s) 118ÿ298ÿ554ÿ368 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Rapport fait à 18:20:37,07 le 26/12/2005
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI.000\Application Data
26/12/2005 12:56 <REP> AVG7
26/12/2005 12:49 62 desktop.ini
26/12/2005 12:49 <REP> ..
26/12/2005 12:49 <REP> Microsoft
26/12/2005 12:49 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
26/12/2005 17:31 <REP> Webroot
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 34952 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> .
2 fichier(s) 35014 octets
26 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
26/12/2005 17:32 820 wrSpySweeperTrialSweep.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .
5 fichier(s) 1ÿ537 octets
2 R‚p(s) 118ÿ298ÿ546ÿ176 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298562560 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI.000\Application Data
26/12/2005 12:56 <REP> AVG7
26/12/2005 12:49 62 desktop.ini
26/12/2005 12:49 <REP> ..
26/12/2005 12:49 <REP> Microsoft
26/12/2005 12:49 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298558464 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
26/12/2005 17:31 <REP> Webroot
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 34952 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> .
2 fichier(s) 35014 octets
26 R‚p(s) 118298554368 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
26/12/2005 17:32 820 wrSpySweeperTrialSweep.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .
5 fichier(s) 1ÿ537 octets
2 R‚p(s) 118ÿ298ÿ554ÿ368 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Rapport fait à 18:20:37,07 le 26/12/2005
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur\Application Data
21/04/2005 11:21 <REP> Identities
21/04/2005 11:14 62 desktop.ini
21/04/2005 11:14 <REP> ..
21/04/2005 11:14 <REP> Microsoft
21/04/2005 11:14 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI\Application Data
20/11/2005 19:35 62 desktop.ini
20/11/2005 19:35 <REP> ..
20/11/2005 19:35 <REP> Microsoft
20/11/2005 19:35 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Administrateur.GUILLAUM-CDJFBI.000\Application Data
26/12/2005 12:56 <REP> AVG7
26/12/2005 12:49 62 desktop.ini
26/12/2005 12:49 <REP> ..
26/12/2005 12:49 <REP> Microsoft
26/12/2005 12:49 <REP> .
1 fichier(s) 62 octets
4 R‚p(s) 118298550272 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\All Users\Application Data
20/12/2005 09:26 <REP> Grisoft
20/12/2005 09:26 <REP> avg7
18/11/2005 11:34 <REP> MSN6
27/10/2005 18:04 <REP> Ulead Systems
24/05/2005 06:20 <REP> Megatech
19/05/2005 18:26 <REP> BOONTY
21/04/2005 09:55 <REP> Spybot - Search & Destroy
19/04/2005 17:32 <REP> Messenger Plus!
19/02/2005 13:27 <REP> Zylom
15/01/2005 17:49 <REP> Skype
07/01/2005 04:24 <REP> Ahead
07/01/2005 04:21 <REP> nView_Profiles
19/12/2004 10:28 <REP> Time bike wipe settings
09/12/2004 20:57 <REP> QuickTime
02/12/2004 12:32 <REP> DVD Shrink
23/11/2004 19:20 <REP> InterVideo
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:35 <REP> Macrovision
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
16/11/2004 17:27 <REP> ..
1 fichier(s) 62 octets
22 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\Default User\Application Data
16/11/2004 17:27 62 desktop.ini
16/11/2004 17:27 <REP> ..
16/11/2004 17:27 <REP> Microsoft
16/11/2004 17:27 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\guillaume\Application Data
03/10/2020 10:48 <REP> Upload flag
26/12/2005 17:31 <REP> Webroot
20/12/2005 09:27 <REP> AVG7
03/12/2005 20:05 <REP> dvdcss
19/11/2005 19:02 <REP> vlc
27/10/2005 18:05 <REP> Ulead Systems
12/08/2005 21:44 <REP> Google
18/06/2005 08:42 <REP> Registry Cleaner
28/03/2005 17:53 <REP> FotoWire
22/02/2005 18:34 <REP> Winds_24
22/02/2005 18:33 <REP> SysDown
18/02/2005 21:48 <REP> Sun
27/01/2005 20:13 <REP> MSN6
23/01/2005 21:33 <REP> Yahoo! Messenger
16/01/2005 14:54 <REP> Shareaza
07/01/2005 04:26 <REP> Ahead
02/01/2005 12:52 <REP> Lavasoft
19/12/2004 10:28 <REP> PlayBib
16/12/2004 19:23 34952 GDIPFONTCACHEV1.DAT
08/12/2004 20:41 <REP> Macromedia
21/11/2004 10:42 <REP> Help
19/11/2004 18:15 <REP> Adobe
18/11/2004 15:19 <REP> Symantec
16/11/2004 17:37 <REP> Identities
16/11/2004 17:37 62 desktop.ini
16/11/2004 17:37 <REP> Microsoft
16/11/2004 17:37 <REP> ..
16/11/2004 17:37 <REP> .
2 fichier(s) 35014 octets
26 R‚p(s) 118298546176 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\Documents and Settings\sauvegarde programmes
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 7837-3FB4
R‚pertoire de C:\WINDOWS\Tasks
26/12/2005 17:32 820 wrSpySweeperTrialSweep.job
19/04/2005 17:30 274 B1A3B15D91282CF1.job
18/11/2004 15:20 372 Symantec NetDetect.job
16/11/2004 17:33 6 SA.DAT
16/11/2004 17:32 65 desktop.ini
16/11/2004 17:32 <REP> ..
16/11/2004 17:32 <REP> .
5 fichier(s) 1ÿ537 octets
2 R‚p(s) 118ÿ298ÿ546ÿ176 octets libres
******************************************
Recherche dans Program files
C:\Program Files\Adv Présent !
Le dossier C:\Program Files\C2Media n'existe pas
*************** Fin du rapport ****************
Bonjour,
Imprime, ou enregistre la manip dans un fichier dans le bloc notes pour être sur ne rien oublier et de tout faire dans l'ordre.
1/Telecharge ceci: Clean Up 40:
http://pageperso.aol.fr/balltrap34/CleanUp40.exe
-aide en image:(merci à Balltrap34).
http://pageperso.aol.fr/balltrap34/democleanup.htm
Déconnecte toi d'Internet et ferme tout les programmes en cours.
Dans ajout/suppression de programmes, desinstalle si tu trouves ceci:
Spyware remover
Security iGuard
Redémarre en mode sans échec
Redémarre le pc, laisse passer l'écran du bios, puis tapote sur la touche F8 avant qu'apparaisse l'écran de chargement de windows.
Choisis le mode sans échec dans les options et valide avec entrée.
(Si F8 ne marche pas, essai F5)
Rend visible les fichiers cachés et système
panneau de configuration > options des dossiers > onglet affichage
Cocher la case devant " afficher les fichiers et dossiers cachés "
Décocher la case devant " masquer les extensions des fichiers dont le type est connu"
Décocher la case devant " masquer les fichiers protégés du système"
clic sur [Appliquer] puis sur [ok] pour valider
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Lance hijackthis et clic sur [do a system scan only]
cocher la case au début des lignes suivantes:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMR Naz5s9cz16Vk2Jp6jlHqzdAG.jsp
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll .dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll .dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
valider en cliquant sur le bouton [fix checked]
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Recherche et supprime ces dossiers:
Supprimer les fichiers en suivant le chemin des fichiers infectés si possible, plutot que d'utiliser la fonction "Rechercher"
S'ils sont présents, supprime:
C:\Documents and Settings\guillaume\Application Data\Upload flag
C:\Program Files\Security iGuard\Security iGuard.exe
C:\WINDOWS\realschd.exe
C:\WINDOWS\shch.exe
C:\WINDOWS\msexploren.exe
C:\Documents and Settings\All Users\Application Data\Time bike wipe settings
c:\Msmsgsis.exe
\winspool.exe
C:\Documents and Settings\guillaume\Application Data\PlayBib
c:\x.cab
c:\eied_s7.cab
c:\ex.cab
C:\Program Files\Adv
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Ensuite fais Démarrer > exécuter et tape cmd
puis valide avec ok
dans la fenêtre qui va s'ouvrir, copie et colle ceci:
del /a C:\WINDOWS\tasks\B1A3B15D91282CF1.job
et valide en appuyant sur entrée
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Ensuite, très important:
:: Supprimer les fichiers temporaires ::
Exécute cleanup40.
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Redémarre normalement et reposte un Hijackthis sur le poste…
Précises moi ou en sont tes soucis…
A+
Imprime, ou enregistre la manip dans un fichier dans le bloc notes pour être sur ne rien oublier et de tout faire dans l'ordre.
1/Telecharge ceci: Clean Up 40:
http://pageperso.aol.fr/balltrap34/CleanUp40.exe
-aide en image:(merci à Balltrap34).
http://pageperso.aol.fr/balltrap34/democleanup.htm
Déconnecte toi d'Internet et ferme tout les programmes en cours.
Dans ajout/suppression de programmes, desinstalle si tu trouves ceci:
Spyware remover
Security iGuard
Redémarre en mode sans échec
Redémarre le pc, laisse passer l'écran du bios, puis tapote sur la touche F8 avant qu'apparaisse l'écran de chargement de windows.
Choisis le mode sans échec dans les options et valide avec entrée.
(Si F8 ne marche pas, essai F5)
Rend visible les fichiers cachés et système
panneau de configuration > options des dossiers > onglet affichage
Cocher la case devant " afficher les fichiers et dossiers cachés "
Décocher la case devant " masquer les extensions des fichiers dont le type est connu"
Décocher la case devant " masquer les fichiers protégés du système"
clic sur [Appliquer] puis sur [ok] pour valider
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Lance hijackthis et clic sur [do a system scan only]
cocher la case au début des lignes suivantes:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tmcniralwvfdppdhuvfkgyjw.com/ZfynToormX_tjr77ah5WBuwf3LJO2Fq6mLxBZOMR Naz5s9cz16Vk2Jp6jlHqzdAG.jsp
O2 - BHO: (no name) - {01D600A2-AE6A-6949-6098-679D404059EE} - C:\DOCUME~1\GUILLA~1\APPLIC~1\UPLOAD~1\DriveJoy.exe (file missing)
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\ccApp.exe /i
O4 - HKLM\..\Run: [TkBellExee] C:\WINDOWS\realschd.exe
O4 - HKLM\..\Run: [Nero] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [Wipe Settings Ball Tick] C:\Documents and Settings\All Users\Application Data\Time bike wipe settings\Bleh intra.exe
O4 - HKLM\..\Run: [Farces & Attrapes] C:\DOCUME~1\GUILLA~1\LOCALS~1\Temp\Rar$EX00.797\shut-shit-and-sex.exe \farces
O4 - HKLM\..\Run: [winspool] \winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\RunServices: [winspool] \winspool.exe
O4 - HKCU\..\Run: [tickdate] C:\DOCUME~1\GUILLA~1\APPLIC~1\PlayBib\4 STUPID.exe
O9 - Extra button: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {0058A23E-6C4F-42EB-AA66-76A3121EC719} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1BFF29EC-F0E0-42C8-9E8C-A2B60802A00E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3FF4E862-74B0-44A0-B7F1-196F3CDA8841} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {404104FC-8851-4450-B168-0CFAB6387AB8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {468CEC5F-5F0A-4B6E-A607-37BF480363D2} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {47453C24-B4BC-4F24-8ADF-9726CB5478F1} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {679118CF-53A4-40BB-A3E6-0608358EE907} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71A5081E-37FE-4BE7-BA15-64F2EF9F549F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {888536A0-0A3B-48F3-AA68-171706D5EEB9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99835422-4111-4830-A106-3A7FA1E4EF63} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9B5311C6-95EC-45A4-A3CB-1ED8C1D4CB71} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9BF82EAA-588C-41A7-B718-3969ECF2C203} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AB714465-4C86-49CC-9E92-235D17C85A6D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D02865B2-1E18-431F-B65D-D38B543C1F23} - (no file) (HKCU)
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {23232323-2323-2323-2323-232323231122} - file://c:\x.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hbtools.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - AppInit_DLLs: bogh7phvumbvx6ll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll .dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll .dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll MsgPlusLoader.dll
valider en cliquant sur le bouton [fix checked]
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Recherche et supprime ces dossiers:
Supprimer les fichiers en suivant le chemin des fichiers infectés si possible, plutot que d'utiliser la fonction "Rechercher"
S'ils sont présents, supprime:
C:\Documents and Settings\guillaume\Application Data\Upload flag
C:\Program Files\Security iGuard\Security iGuard.exe
C:\WINDOWS\realschd.exe
C:\WINDOWS\shch.exe
C:\WINDOWS\msexploren.exe
C:\Documents and Settings\All Users\Application Data\Time bike wipe settings
c:\Msmsgsis.exe
\winspool.exe
C:\Documents and Settings\guillaume\Application Data\PlayBib
c:\x.cab
c:\eied_s7.cab
c:\ex.cab
C:\Program Files\Adv
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Ensuite fais Démarrer > exécuter et tape cmd
puis valide avec ok
dans la fenêtre qui va s'ouvrir, copie et colle ceci:
del /a C:\WINDOWS\tasks\B1A3B15D91282CF1.job
et valide en appuyant sur entrée
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Ensuite, très important:
:: Supprimer les fichiers temporaires ::
Exécute cleanup40.
-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_
Redémarre normalement et reposte un Hijackthis sur le poste…
Précises moi ou en sont tes soucis…
A+
Enfin j'ai fini!!!! J'espère que je n'en ai pas oublié; tu me dira ça. Je vais manger un bout , premier repas de la journée. Merci pour ton aide ta gentillesse et ta compréhension, c'est pas donné à tout le monde. A++++
Logfile of HijackThis v1.99.1
Scan saved at 20:15:13, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\DrvMon.exe
C:\program files\steam\steam.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 20:15:13, on 26/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\DrvMon.exe
C:\program files\steam\steam.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.rd.yahoo.com/customize/ie/defaults/stp/ymsgr6/fr/*http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/ymsgr6/fr/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: Yahoo! Compagnon - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_18_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Fichiers communs\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\System32\DrvMon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MSI Media Center Deluxe II.lnk = C:\Program Files\MSI\Media Center Deluxe II\Projector.exe
O4 - Global Startup: WinIRXHelper.lnk = C:\Program Files\MSI\Media Center Deluxe II\WinIRXHelper.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7C7F5114-9B67-4BE3-920D-835993001D7F} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102774868140
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
salut
Rend toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clik sur parcourir
Recherche ceci :
c:\program files\topthemesxp\txp.exe
Clik send et colle le rapport stp
A+
Rend toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clik sur parcourir
Recherche ceci :
c:\program files\topthemesxp\txp.exe
Clik send et colle le rapport stp
A+
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nwcyrkrrcoxzbjwwfr.com/teuKzWGmdUqhh0FdaiVHZqHNdkiLms7TC4i6qNw1aoc.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.unika.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/ServicesAcces.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {177781D8-3C66-B027-A6C9-6122C0E12582} - C:\DOCUME~1\Audrey\APPLIC~1\KINDWI~1\BitsBleh.exe
O2 - BHO: (no name) - {4CB4747E-A1B8-B47F-F0F0-7AC40434BD4E} - C:\DOCUME~1\Audrey\APPLIC~1\KINDWI~1\BitsBleh.exe
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [winspool] C:\WINDOWS\system32\dllcache\winspool.exe
O4 - HKLM\..\Run: [Msmsgsis.exe] c:\Msmsgsis.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [cast seek support flaw] C:\Documents and Settings\All Users\Application Data\regs ace cast seek\4readme.exe
O4 - HKLM\..\RunServices: [winspool] C:\WINDOWS\system32\dllcache\winspool.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [flap wipe] C:\DOCUME~1\Audrey\APPLIC~1\CHICAIM\gram atom.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.unika.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
Voila se que sa me met a moi !