[Ezula et Web offer]

yo 35 Messages postés 13 Statut Membre -  
Kristopher Messages postés 3752 Statut Contributeur -
Bonsoir,

Problème au démarrage avec Ezula et Web offer.

Voici mon log Hitjackthis.

Merci d'avance pour votre aide.

Logfile of HijackThis v1.99.1
Scan saved at 21:49:21, on 13/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\Utilisateur\Application Data\??stem\msiexec.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
c:\program files\softwin\bitdefender free edition\bdmcon.exe
C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
C:\Documents and Settings\Utilisateur\Bureau\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BDNewsAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [Sp2Protect] C:\WINDOWS\system32\sp2protect.exe
O4 - HKLM\..\Run: [Bluetooth] C:\WINDOWS\system32\shell32.exe
O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\system32\wudupdate.exe
O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\system32\username.exe
O4 - HKLM\..\Run: [I download pirated Software] C:\WINDOWS\system32\_.gof
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
O4 - HKLM\..\Run: [MMC Recovery] C:\WINDOWS\system32\drsmartload261a.exe
O4 - HKLM\..\Run: [Local Authority Service] C:\WINDOWS\system32\drsmartload261a.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard9.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad9.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname9.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [System service79] C:\WINDOWS\etb\pokapoka79.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [mrwm] C:\PROGRA~1\FICHIE~1\mrwm\mrwmm.exe
O4 - HKCU\..\Run: [Auro] "C:\DOCUME~1\UTILIS~1\APPLIC~1\YMANTE~1\arpa.exe" -vt ndrv
O4 - HKCU\..\Run: [Vqattywe] C:\Documents and Settings\Utilisateur\Application Data\??stem\msiexec.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\RunOnce: [Web Offer] C:\WINDOWS\system32\ezPopStub.exe /UninstPOP2 C:\Program Files\Web Offer
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/fr/4,0,0,83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/fr/1,0,0,20/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\ir8sl5l71.dll (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

17 réponses

  1. yo 35 Messages postés 13 Statut Membre
     
    et voici le nouveau log :

    Logfile of HijackThis v1.99.1
    Scan saved at 00:13:22, on 14/04/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Documents and Settings\Utilisateur\Application Data\??stem\msiexec.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
    C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
    c:\program files\softwin\bitdefender free edition\bdmcon.exe
    C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Utilisateur\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - Default URLSearchHook is missing
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [BDNewsAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
    O4 - HKLM\..\Run: [Sp2Protect] C:\WINDOWS\system32\sp2protect.exe
    O4 - HKLM\..\Run: [Bluetooth] C:\WINDOWS\system32\shell32.exe
    O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\system32\wudupdate.exe
    O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\system32\username.exe
    O4 - HKLM\..\Run: [I download pirated Software] C:\WINDOWS\system32\_.gof
    O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
    O4 - HKLM\..\Run: [MMC Recovery] C:\WINDOWS\system32\drsmartload261a.exe
    O4 - HKLM\..\Run: [Local Authority Service] C:\WINDOWS\system32\drsmartload261a.exe
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard9.exe
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad9.exe
    O4 - HKLM\..\Run: [newname] C:\windows\newname9.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [System service79] C:\WINDOWS\etb\pokapoka79.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [mrwm] C:\PROGRA~1\FICHIE~1\mrwm\mrwmm.exe
    O4 - HKCU\..\Run: [Auro] "C:\DOCUME~1\UTILIS~1\APPLIC~1\YMANTE~1\arpa.exe" -vt ndrv
    O4 - HKCU\..\Run: [Vqattywe] C:\Documents and Settings\Utilisateur\Application Data\??stem\msiexec.exe
    O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
    O4 - HKCU\..\RunOnce: [Web Offer] C:\WINDOWS\system32\ezPopStub.exe /UninstPOP2 C:\Program Files\Web Offer
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe
    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/fr/4,0,0,83/mcinsctl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/fr/1,0,0,20/mcgdmgr.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\ir8sl5l71.dll (file missing)
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

    J'espère que tu pourras m'aider, mais là je dois azller au dodo car Boulot Demain
    0
  2. regis56 Messages postés 173 Statut Membre 2
     
    Bonsoir !

    Peut tu faire ceci !

    (auteur Kristopher )
    Si vous avez un doute quant à la bonne santé de votre PC, cela peut être la manifestation des prodromes d'une quelconque infection...

    Dans le dessein de gagner en vitesse et en efficacité, je vous expose une méthode préliminaire qu'il faut impérativement effectuer intégralement et dans l'ordre !

    Note : Pour effectuer ces opérations, il est inutile de désactiver ou de désinstaller le(s) système(s) de protection (Antivirus, Pare-feu ou autres applications)

    -----------------------------------------------------------------------------------------------------------

    1/ Télécharger et scanner son PC avec Ewido Security Suite : https://www.01net.com/404/
    Copier/coller le rapport entier sur le forum.

    Regarder la démo d'utilisation :
    http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
    (Merci à mOe pour cette réalisation)

    2/ Scanner son PC avec cet antivirus en ligne (sous Internet Explorer) :
    https://www.bitdefender.com/toolbox/
    Cliquer sur "I Agree" et scanner tout le PC.
    Penser à accepter l'ActiveX bloqué par la barre anti-popup du SP2 (elle clignotera en haut).
    Copier/coller le rapport entier sur le forum.

    3/ Télécharger HijackThis :
    https://www.01net.com/404/
    - L'installer dans son propre dossier.
    Par exemple, C:HijackThis
    - Choisir l'option "do a scan and a logfile", attendre que le log se génère puis copier et coller le rapport sur le forum.

    Regarder la démo d'utilisation :
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    (Merci à balltrap34 pour cette réalisation)

    -----------------------------------------------------------------------------------------------------------

    Une fois toutes ces manipulations effectuées, votre PC devrait être d'ores et déjà moins infecté.

    Néanmoins, afin de s'en assurer, je vous invite à poster les 3 rapports sur le Forum virus/sécurité et moi-même ou un autre membre vous guidera pour la suite.

    A plus !
    0
    1. yo 35 Messages postés 13 Statut Membre
       
      Le log que j'ai collé n'est pas suffissant ?
      0
    2. yo 35 Messages postés 13 Statut Membre
       
      Car j'ai déjà Ewido ,Bitdefender et également Mac Afee
      0
  3. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir,

    Vu ton log, ce que te demande Régis56 est le minimum !
    Il va avoir du boulot !

    Bon courage à vous deux.

    A+

    0
  4. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Re,

    tant que j'y suis et pour avancer Régis,

    telecharge SmitfraudFix

    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
    Copie/colle le sur le poste stp.

    voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php

    Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).
    ----------------------------------------------------------------------------
    Relance le programme Smitfraud,
    Cette fois choisit l’option 2, répond oui a tous ;
    Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

    Relance hijackthis et colle un nouveau log ici.

    Bonne nuit.

    A+
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. yo 35 Messages postés 13 Statut Membre
     
    Vous m'inquiétez c'est si grave que ça au regard de mon log
    0
  7. regis56 Messages postés 173 Statut Membre 2
     
    t'inquiéte pas on vas y arrivé ;)
    0
  8. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Re,

    avant d'aller au dodo, tout ça ces des virus and Co (et j'en oublie !) :

    [Sp2Protect] C:\WINDOWS\system32\sp2protect.exe
    O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\system32\wudupdate.exe
    O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\system32\username.exe
    O4 - HKLM\..\Run: [I download pirated Software] C:\WINDOWS\system32\_.gof
    O4 - HKLM\..\Run: [MMC Recovery] C:\WINDOWS\system32\drsmartload261a.exe
    O4 - HKLM\..\Run: [Local Authority Service] C:\WINDOWS\system32\drsmartload261a.exe
    O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard9.exe
    O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad9.exe
    O4 - HKLM\..\Run: [newname] C:\windows\newname9.exe
    C:\WINDOWS\etb\pokapoka79.exe

    mais vous trouverez ici, toute l'aide possible pour vous en débarasser

    A+

    0
  9. incognito02 Messages postés 3487 Statut Contributeur 138
     
    Bonsoir Régis :-)

    je te laisse le bébé ! lol

    Bon courage.

    A+

    0
  10. regis56 Messages postés 173 Statut Membre 2
     
    Merci et bonne nuit incognito02
    0
  11. yo 35 Messages postés 13 Statut Membre
     
    Excuse moi mais c'est possible de lancer plusieurs scan à la fois ou il faut les faire un à un.

    Ewido est presque terminé

    Désolé je débute en info
    0
  12. yo 35 Messages postés 13 Statut Membre
     
    Voilà pour Ewido

    ---------------------------------------------------------
    ewido anti-malware - Rapport de scan
    ---------------------------------------------------------

    + Créé le: 22:36:34, 13/04/2006
    + Somme de contrôle: 3E2CF58D

    + Résultats du scan:

    HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\AppID\eZulaMain.EXE -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.eZulaCtrlHost.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaAgent.PlugProt.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\eZulaAgent.ToolBarBand.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.eZulaSearchPipe.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CLSID -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM\CurVer -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\EZulaMain.TrayIConM.1 -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula -> Adware.Ezula : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer -> Adware.Ezula : Nettoyer et sauvegarder
    HKU\S-1-5-21-2025429265-1844823847-725345543-1004\Software\eZula -> Adware.Ezula : Nettoyer et sauvegarder
    HKU\S-1-5-21-2025429265-1844823847-725345543-1004\Software\eZula\Setup -> Adware.Ezula : Nettoyer et sauvegarder
    HKU\S-1-5-21-2025429265-1844823847-725345543-1004\Software\eZula\Setup\ID -> Adware.Ezula : Nettoyer et sauvegarder
    HKU\S-1-5-21-2025429265-1844823847-725345543-1004\Software\eZula\Setup\path -> Adware.Ezula : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@247realmedia[2].txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@com[1].txt -> TrackingCookie.Com : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@estat[1].txt -> TrackingCookie.Estat : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@wreport.weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
    C:\Documents and Settings\Utilisateur\Cookies\utilisateur@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder

    ::Fin du rapport
    0
  13. yo 35 Messages postés 13 Statut Membre
     
    Voici le rapport Bit Defender :

    BitDefender Online Scanner

    Scan report generated at: Thu, Apr 13, 2006 - 23:59:52

    Scan path: C:\;D:\;E:\;F:\;

    Statistics

    Time
    01:19:51

    Files
    380031

    Folders
    4815

    Boot Sectors
    3

    Archives
    1973

    Packed Files
    11809

    Results

    Identified Viruses
    26

    Infected Files
    125

    Suspect Files
    0

    Warnings
    0

    Disinfected
    0

    Deleted Files
    125

    Engines Info

    Virus Definitions
    369771

    Engine build
    AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

    Scan plugins
    13

    Archive plugins
    39

    Unpack plugins
    4

    E-mail plugins
    6

    System plugins
    1

    Scan Settings

    First Action
    Disinfect

    Second Action
    Delete

    Heuristics
    Yes

    Enable Warnings
    Yes

    Scanned Extensions
    *;

    Exclude Extensions

    Scan Emails
    Yes

    Scan Archives
    Yes

    Scan Packed
    Yes

    Scan Files
    Yes

    Scan Boot
    Yes

    Scanned File
    Status

    C:\Documents and Settings\Utilisateur\Local Settings\Temp\Temporary Internet Files\Content.IE5\KQFJMT8Y\ovh[1].swf=>[SWF command]
    Infected with: Trojan.SwfDL.A

    C:\Documents and Settings\Utilisateur\Local Settings\Temp\Temporary Internet Files\Content.IE5\KQFJMT8Y\ovh[1].swf=>[SWF command]
    Deleted

    C:\Documents and Settings\Utilisateur\Local Settings\Temp\Temporary Internet Files\Content.IE5\KQFJMT8Y\ovh[1].swf
    Update failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006306.dll
    Infected with: Trojan.Downloader.Small.AMG

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006306.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006306.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006313.exe
    Infected with: Trojan.Downloader.VB.AAD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006313.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006313.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006365.dll
    Infected with: Trojan.Downloader.Small.AMG

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006365.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006365.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006377.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006377.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006377.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006384.exe
    Infected with: Trojan.Downloader.VB.AAD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006384.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006384.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006397.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006397.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006397.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006399.dll
    Infected with: Trojan.Downloader.Small.AMG

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006399.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006399.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006401.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006401.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006408.exe
    Infected with: Trojan.Downloader.VB.AAD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006408.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006408.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006414.exe
    Infected with: Trojan.Downloader.Small.BUY

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006414.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006415.exe
    Infected with: Trojan.Downloader.TSUpdate.P

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006415.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006416.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006416.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006427.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006427.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006435.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006435.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006436.exe
    Infected with: Trojan.Canbede.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006436.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006436.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006437.exe
    Infected with: Trojan.Proxy.493

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006437.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006437.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006438.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006438.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006438.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006442.dll
    Infected with: Trojan.Downloader.Small.AMG

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006442.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006442.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006443.exe
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006443.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006443.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006446.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006446.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006446.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006447.dll
    Infected with: Trojan.Isbar.230

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006447.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006447.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006448.dll
    Infected with: Trojan.Isbar.230

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006448.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006448.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006449.exe
    Infected with: Trojan.Proxy.493

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006449.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006449.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006453.dll
    Infected with: Trojan.Downloader.IstBar.OL

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006453.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006453.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006454.dll
    Infected with: Trojan.Downloader.IstBar.OL

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006454.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006454.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006455.exe
    Infected with: Trojan.SillyDl.IT

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006455.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006455.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006456.exe
    Infected with: Trojan.Winad.18037.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006456.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006456.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006457.exe
    Infected with: Trojan.Downloader.TSUpdate.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006457.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006458.exe
    Infected with: Trojan.Downloader.Tsupdate.N

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006458.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006458.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006459.exe
    Infected with: Trojan.Downloader.Tsupdate.F

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006459.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006459.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006460.dll
    Infected with: Trojan.Downloader.Dyfuca.DD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006460.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006461.exe
    Infected with: Trojan.Dnschange.F

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006461.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006461.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006465.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006465.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006465.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006466.exe
    Infected with: Trojan.Dropper.Agent.NY

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006466.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006466.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006471.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006471.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006471.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006472.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006472.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006472.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006473.exe
    Infected with: Trojan.Downloader.Tsupdate.N

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006473.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006473.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006475.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006475.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006475.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006476.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006476.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006476.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006480.exe
    Infected with: Trojan.Downloader.Istbar.SD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006480.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006480.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006482.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006482.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006490.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0006490.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007489.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007489.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007496.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007496.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007510.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007510.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007522.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007522.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007617.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007617.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007629.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007629.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007638.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007638.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007648.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007648.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007649.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007649.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007652.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007652.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007658.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007658.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007689.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007689.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007700.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007700.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007722.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007722.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007722.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007731.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP55\A0007731.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007734.exe
    Infected with: Trojan.Canbede.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007734.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007734.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007735.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007735.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007735.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007737.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007737.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007738.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007738.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007739.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007739.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007741.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007741.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007745.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007745.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007782.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007782.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007790.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007790.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007790.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007794.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007794.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007799.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007799.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007805.exe
    Infected with: Trojan.Downloader.Dyfuca.EX

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007805.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007805.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007820.exe
    Infected with: Trojan.Dnschange.F

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007820.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007820.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007822.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007822.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007822.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007823.exe
    Infected with: Trojan.Downloader.Small.BUY

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007823.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007824.exe
    Infected with: Trojan.Canbede.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007824.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007824.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007840.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007840.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007843.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007843.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007850.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007850.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007854.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007854.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP56\A0007854.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007865.exe
    Infected with: Trojan.Canbede.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007865.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007865.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007866.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007866.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0007866.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008863.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008863.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008869.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008869.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008881.dLL
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008881.dLL
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008881.dLL
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008888.exe
    Infected with: Trojan.Downloader.Small.BUY

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008888.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008889.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008889.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008890.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008890.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008891.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008891.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008892.exe
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008892.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008892.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008893.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008893.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008893.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008894.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008894.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008894.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008896.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008896.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008905.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008905.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008905.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008914.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008914.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008918.dll
    Infected with: Trojan.Candebe.CZ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008918.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008918.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008922.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008922.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008922.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008923.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008923.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008924.exe
    Infected with: Trojan.Dnschange.F

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008924.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008924.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008925.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008925.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008925.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008932.exe
    Infected with: Trojan.Downloader.Small.BUY

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008932.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008933.exe
    Infected with: Trojan.Canbede.L

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008933.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008933.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008938.exe
    Infected with: Trojan.Downloader.Tsupdate.O

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008938.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008938.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008940.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008940.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008940.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008942.exe
    Infected with: Trojan.Downloader.VB.AAD

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008942.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008942.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008945.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008945.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008948.exe
    Infected with: Trojan.Dropper.Vb.KK

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008948.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP57\A0008948.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009210.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009210.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009260.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009260.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009312.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009312.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009316.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009316.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009330.exe
    Infected with: Trojan.Isbar.N

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009330.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009330.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009333.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009333.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009337.exe
    Infected with: Trojan.Downloader.IstBar.IJ

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009337.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009339.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009339.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009339.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009360.exe
    Infected with: Trojan.Dnschange.F

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009360.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009360.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009370.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009370.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009371.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009371.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009391.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009391.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009392.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009392.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009404.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009404.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009405.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009405.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009414.dll
    Detected with: Adware.Dinky.A.Trojan

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP58\A0009414.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009529.exe
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009529.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009529.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009535.exe
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009535.exe
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009535.exe
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009554.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009554.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009554.dll
    Deleted

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009555.dll
    Detected with: Adware.Weboffer.A

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009555.dll
    Disinfection failed

    C:\System Volume Information\_restore{60D5D05D-F4DC-43B8-A581-5970B7D62B3B}\RP60\A0009555.dll
    Deleted
    0
  14. regis56 Messages postés 173 Statut Membre 2
     
    Bonjour !

    On va commencer comme ceci

    option 1

    (WinXP, Win2K)
    Télécharger SmitfraudFix de S!Ri sur http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Dézipper la totalité de l'archive smitfraudfix.zip

    Utilisation ----- option 1 - Recherche :
    Double cliquer sur smitfraudfix.cmd
    Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.
    Poster le rapport sur le forum.

    process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

    Ensuite fais ceci
    option 2

    Utilisation ----- option 2 -Nettoyage :
    Redémarrer l'ordinateur en mode sans échec (tapoter F8 au boot pour obtenir le menu de démarrage
    ou tuto Symantec).

    Double cliquer sur smitfraudfix.cmd
    Sélectionner 2 pour supprimer les fichiers responsables de l'infection.
    A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran
    et supprimer les clés de démarrage automatique de l'infection.
    Le fix déterminera si le fichier wininet.dll est infecté.
    A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.
    Redémarrer en mode normal et poster le rapport plus un rapport hijackthis sur le forum.

    N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1
    Attention : l'option 2 de l'outil supprime le fond d'écran !

    process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

    A plus !
    0
  15. yo 35 Messages postés 13 Statut Membre
     
    Bonjour,

    Quand j'extrait les fichers dans un dossier spécifié le fichier smitfraudfix.cmd n'apparait pas ou autrement il me précise que le fichier process.exe est introuvable
    0
    1. Kristopher Messages postés 3752 Statut Contributeur 106
       
      Bonjour à tous,

      yo 35, on réessaie :

      - Télécharge le logiciel SmitfraudFix sur le site :
      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
      - Tu enregistres le logiciel sur le bureau pour faire plus simple.
      Puisqu'il est zippé, tu dois le dezippé.
      Si tu utilises Winrar, tu fais : "clique droit" - > "Extraire Ici".
      Tu auras un dossier nommé "SmitfraudFix" qui va apparaître.

      - Tu ouvres le ce dossier, double-clique sur "Smitfraudfix.cmd", choisit l’option 1, il va générer un rapport.

      Copie et colle le sur le poste.

      ++
      0
  16. yo 35 Messages postés 13 Statut Membre
     
    Voici le rapport
    0
  17. yo 35 Messages postés 13 Statut Membre
     
    Voici mon rapport :

    SmitFraudFix v2.29

    Rapport fait à 15:21:25,07, 15/04/2006
    Executé à partir de C:\Documents and Settings\Utilisateur\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\amcompat.tlb PRESENT !
    C:\WINDOWS\system32\nscompat.tlb PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="C:\\WINDOWS\\system32\\ad.html"
    "SubscribedURL"=""
    "FriendlyName"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"

    [HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\system32\browseui.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\system32\browseui.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

    [HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\system32\browseui.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\system32\browseui.dll"

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
  18. Kristopher Messages postés 3752 Statut Contributeur 106
     
    Hello

    Bon bah c'est cool, je vois que mon explication a marché ;)

    Maintenant, fais cette manipulation :

    - Redémarre le PC en mode "sans échec" : tu tapotes sur la touche F8 de ton clavier (ou bien F5 selon la version de Windows) et tu choisis le mode "sans échec".

    - Tu relances SmitfraudFix cette fois-ci en choisissant l'option 2 et tu réponds oui à tout.

    Colle le nouveau rapport ensuite.

    Et je laisse l'ami regis56 s'occuper du reste ;)

    Courage, Kristopher.

    ++
    0