[ Virus ?] System Alert : Malware threats
Marc06
Messages postés
14
Statut
Membre
-
www -
www -
Bonjour tout le monde, je susi un petit nouveau, et j'aurait besoin d'aide.
Dans ma barre en bas à droite de l'écran un icone triangulaire jaune avec un point d'exclamation noire clignote. Une bulle apparait, il y a inscrit : "System Alert : Malware threats . Your computer is infected with a back door Trojan that allows the remote attacker to perform various malicious actions. Click this baloon to download malware removal software".
Si je clique sur cette bulle, sa m'envoie sur le site MalwareWipe, un antivirus payant.
J'ai fait une analyse avec mon antivivrus perso (Bit Defender), il n'a rien trouver d'anormal.
Que doit-je faire?
Sa serait vraiment super sympa si quelqu'un pouvait me donner un coup de main.
Merci d'avance.
Configuration :
Je mis connait pas tro en config.
Je sait seulement que j'ai Windows XP familiale.
Processeur 1,60 GHz
512 Mo de RAM
A+
Dans ma barre en bas à droite de l'écran un icone triangulaire jaune avec un point d'exclamation noire clignote. Une bulle apparait, il y a inscrit : "System Alert : Malware threats . Your computer is infected with a back door Trojan that allows the remote attacker to perform various malicious actions. Click this baloon to download malware removal software".
Si je clique sur cette bulle, sa m'envoie sur le site MalwareWipe, un antivirus payant.
J'ai fait une analyse avec mon antivivrus perso (Bit Defender), il n'a rien trouver d'anormal.
Que doit-je faire?
Sa serait vraiment super sympa si quelqu'un pouvait me donner un coup de main.
Merci d'avance.
Configuration :
Je mis connait pas tro en config.
Je sait seulement que j'ai Windows XP familiale.
Processeur 1,60 GHz
512 Mo de RAM
A+
A voir également:
- [ Virus ?] System Alert : Malware threats
- Reboot system now - Guide
- Virus mcafee - Accueil - Piratage
- Cette action ne peut pas être réalisée car le fichier est ouvert dans system - Guide
- Mail delivery system ✓ - Forum Virus
- Fichier ouvert dans system ✓ - Forum Windows
18 réponses
bon bah tu semble infecté, donc:
Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici s
Ewido: (reste gratuit après la période d'essai)
Ewido
Puis scanne ton Pc avec ces deux atres logiciels et supprime ce qu'ils pourraient te trouver
SpyBot-Search & Destroy: (gratuit)
Spybot
A² squared: (gratuit)
A-squared
Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici s
Ewido: (reste gratuit après la période d'essai)
Ewido
Puis scanne ton Pc avec ces deux atres logiciels et supprime ce qu'ils pourraient te trouver
SpyBot-Search & Destroy: (gratuit)
Spybot
A² squared: (gratuit)
A-squared
Salut,
Télécharge HijackThis:
http://www.infos-du-net.com/telecharger/HijackThis.html
Installe le dans son propre dossier:
-clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
Lance le, clic sur "do a system scan and save logfile"
Puis copie et colle le rapport ici stp
Télécharge HijackThis:
http://www.infos-du-net.com/telecharger/HijackThis.html
Installe le dans son propre dossier:
-clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
Lance le, clic sur "do a system scan and save logfile"
Puis copie et colle le rapport ici stp
Voici le rapport :
Logfile of HijackThis v1.99.1
Scan saved at 13:52:05, on 26/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\Program Files\TrueCodec\isamonitor.exe
C:\Program Files\TrueCodec\pmsngr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\SurfAccuracy\SAcc.exe
C:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\softwin\BITDEF~1\bdswitch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\TrueCodec\pmmon.exe
C:\Program Files\TrueCodec\isamini.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\TEMP\Bureau\Nouveau dossier\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\Program Files\YourSiteBar\ysb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\TrueCodec\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdswitch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Merci de bien vouloir faire se que tu peut pour m'aider.
Logfile of HijackThis v1.99.1
Scan saved at 13:52:05, on 26/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\Program Files\TrueCodec\isamonitor.exe
C:\Program Files\TrueCodec\pmsngr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\SurfAccuracy\SAcc.exe
C:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\softwin\BITDEF~1\bdswitch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\TrueCodec\pmmon.exe
C:\Program Files\TrueCodec\isamini.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\TEMP\Bureau\Nouveau dossier\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\Program Files\YourSiteBar\ysb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\TrueCodec\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [BDMCon] c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\softwin\BITDEF~1\bdswitch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Merci de bien vouloir faire se que tu peut pour m'aider.
bonsoir voila le rapport de l'analyse j'attend une reponse pour savoir ce que je doi faire par la suite,merci
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:50:43, on 01/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\HyperTechnologies\Deep Freeze\DfServEx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HyperTechnologies\Deep Freeze\_$Df\FrzState.exe
C:\Program Files\Video ActiveX Access\imsmain.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Video ActiveX Access\imsmn.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Menara\dslmon.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\PROGRA~1\FICHIE~1\MICROS~1\DW\DWTRIG20.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Bureau\Scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.menara.ma/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.menara.ma/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera LTI301P
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SeePassword] C:\Program Files\SeePassword\SeePassword.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Video ActiveX Access\imsmain.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Video ActiveX Access\iesmn.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D57ECEBF-D97A-48B4-9519-019C7B3E21A2}: NameServer = 212.217.0.13 212.217.1.4
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: amaretti - {2fdde73c-273e-4e55-84dc-455de06e4866} - (no file)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: DFServEx - Hyper Technologies Inc. - C:\Program Files\HyperTechnologies\Deep Freeze\DfServEx.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:50:43, on 01/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\HyperTechnologies\Deep Freeze\DfServEx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HyperTechnologies\Deep Freeze\_$Df\FrzState.exe
C:\Program Files\Video ActiveX Access\imsmain.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Video ActiveX Access\imsmn.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Ares\Ares.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Menara\dslmon.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\PROGRA~1\FICHIE~1\MICROS~1\DW\DWTRIG20.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Bureau\Scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.menara.ma/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.menara.ma/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Menara
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera LTI301P
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SeePassword] C:\Program Files\SeePassword\SeePassword.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Video ActiveX Access\imsmain.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Video ActiveX Access\iesmn.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D57ECEBF-D97A-48B4-9519-019C7B3E21A2}: NameServer = 212.217.0.13 212.217.1.4
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: amaretti - {2fdde73c-273e-4e55-84dc-455de06e4866} - (no file)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: DFServEx - Hyper Technologies Inc. - C:\Program Files\HyperTechnologies\Deep Freeze\DfServEx.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Refais un scanne avec Ewido car: No action taken veut dire qu'il n'a rien supprimer, tu choisis "delete" dès que le scanne est fini, puis colle à nouveau le rapport ici
Ensuite:
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
Ensuite:
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
Je pense que cette fois c'est bon. Voici le rapport de Ewido :
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:22:58 26/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : No action taken.
HKU\S-1-5-21-1644491937-839522115-682003330-1004\Software\Internet Security -> Adware.IntCodec : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historyfiles -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historysearch_term -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\PowerScan -> Adware.PowerScan : No action taken.
C:\Program Files\SideFind -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_f_b_h_o_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_i_d_e_f_i_n_d_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\sfexd001 -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\update -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Microsoft\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind\History -> Adware.SideFind : No action taken.
[1672] C:\Program Files\SideFind\sfbho.dll -> Adware.SideFind : No action taken.
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\License.lnk -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\__delete_on_reboot__S_A_c_c_._e_x_e_ -> Adware.SurfAccuracy : No action taken.
C:\WINDOWS\vweksplo.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\Fichiers communs\WinSoftware\CrXML.dll -> Adware.Winfixer : No action taken.
C:\Program Files\YourSiteBar -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\imagemap_normal.bmp -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\version.txt -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\yoursitebar.xml -> Adware.YourSiteBar : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@112.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adjuggler[2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@servedby.advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\maison\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bfast[2].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bfast[1].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads13.bpath[1].txt -> TrackingCookie.Bpath : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinotropez[1].txt -> TrackingCookie.Casinotropez : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.clubdicecasino[1].txt -> TrackingCookie.Clubdicecasino : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bilbo.counted[2].txt -> TrackingCookie.Counted : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\maison\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as-eu.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\maison\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-adteractive.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-bluesouth.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-foxmovies.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-mybc.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-netquote.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-nokiafin.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-ogilvy.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-yvesrocher.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nestlefr.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-sonyesolutions.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hotlog[1].txt -> TrackingCookie.Hotlog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sales.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\maison\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\maison\Cookies\maison@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.planetactive[2].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\maison\Cookies\maison@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.sidefind[1].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[2].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[3].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@spylog[1].txt -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@anad.tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\maison\Cookies\maison@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tradedoubler[4].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@pr.valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@wreport.weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\maison\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\maison\Cookies\maison@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
::Report end
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:22:58 26/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : No action taken.
HKU\S-1-5-21-1644491937-839522115-682003330-1004\Software\Internet Security -> Adware.IntCodec : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historyfiles -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historysearch_term -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\PowerScan -> Adware.PowerScan : No action taken.
C:\Program Files\SideFind -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_f_b_h_o_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_i_d_e_f_i_n_d_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\sfexd001 -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\update -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Microsoft\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind\History -> Adware.SideFind : No action taken.
[1672] C:\Program Files\SideFind\sfbho.dll -> Adware.SideFind : No action taken.
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\License.lnk -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\__delete_on_reboot__S_A_c_c_._e_x_e_ -> Adware.SurfAccuracy : No action taken.
C:\WINDOWS\vweksplo.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\Fichiers communs\WinSoftware\CrXML.dll -> Adware.Winfixer : No action taken.
C:\Program Files\YourSiteBar -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\imagemap_normal.bmp -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\version.txt -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\yoursitebar.xml -> Adware.YourSiteBar : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@112.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adjuggler[2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@servedby.advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\maison\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bfast[2].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bfast[1].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads13.bpath[1].txt -> TrackingCookie.Bpath : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinotropez[1].txt -> TrackingCookie.Casinotropez : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.clubdicecasino[1].txt -> TrackingCookie.Clubdicecasino : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bilbo.counted[2].txt -> TrackingCookie.Counted : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\maison\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as-eu.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\maison\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-adteractive.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-bluesouth.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-foxmovies.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-mybc.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-netquote.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-nokiafin.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-ogilvy.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-yvesrocher.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nestlefr.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-sonyesolutions.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hotlog[1].txt -> TrackingCookie.Hotlog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sales.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\maison\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\maison\Cookies\maison@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.planetactive[2].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\maison\Cookies\maison@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.sidefind[1].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[2].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[3].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@spylog[1].txt -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@anad.tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\maison\Cookies\maison@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tradedoubler[4].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@pr.valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@wreport.weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\maison\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\maison\Cookies\maison@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
::Report end
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
c'est toujours ça lol :D
dès que le scan est fini il devrait t'indiquer pour mettre en quarantaine ou "delete" faut tu choisisses l'un des deux ;-)
dès que le scan est fini il devrait t'indiquer pour mettre en quarantaine ou "delete" faut tu choisisses l'un des deux ;-)
Je croit que mon probléme commence a étre trés grave.
J'ai le triangle jaune avec le point d'exclamation noir, qui clignote, qui s'affiche de plus en plus souvent avec plusieurs message d'erreur différent. Si je clique sur les bulles, cela m'envoie sur le site d'un produit antivirus ou autre, payant.
J'ai de nombreux pop-up qui apparaise intempestivement, notament des pubs pour des antivirus.
De plus lorsque je lance Internet Explorer, sa ne m'affiche pas ma page d'acceuil abituelle (orange.fr), mais un autre site (http://iehomepages.com/).
Que doit-je faire?
Merci d'avance de bien vouloir me guider, car sa commence à vraiment m'inquiéter tout sa.
J'ai le triangle jaune avec le point d'exclamation noir, qui clignote, qui s'affiche de plus en plus souvent avec plusieurs message d'erreur différent. Si je clique sur les bulles, cela m'envoie sur le site d'un produit antivirus ou autre, payant.
J'ai de nombreux pop-up qui apparaise intempestivement, notament des pubs pour des antivirus.
De plus lorsque je lance Internet Explorer, sa ne m'affiche pas ma page d'acceuil abituelle (orange.fr), mais un autre site (http://iehomepages.com/).
Que doit-je faire?
Merci d'avance de bien vouloir me guider, car sa commence à vraiment m'inquiéter tout sa.
Finalement je susi arriver a "delete". Donc voici le rapport.
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 21:43:49 26/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : Cleaned.
HKU\S-1-5-21-1644491937-839522115-682003330-1004\Software\Internet Security -> Adware.IntCodec : Cleaned.
C:\Documents and Settings\TEMP\Local Settings\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\Cache\6F4BFF4Ad01 -> Not-A-Virus.Downloader.Win32.WinFixer.m : Cleaned.
:mozilla.63:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.64:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.578:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.870:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.874:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.884:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.886:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.939:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.847:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.882:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.890:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.945:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.791:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.792:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.849:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.38:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.84:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.59:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads13.bpath[1].txt -> TrackingCookie.Bpath : Cleaned.
:mozilla.365:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bilbo.counted[2].txt -> TrackingCookie.Counted : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.45:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.28:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.347:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-nestlefr.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-sonyesolutions.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.575:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.626:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.867:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.29:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.30:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads.planetactive[2].txt -> TrackingCookie.Planetactive : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.799:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.800:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.801:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.564:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.586:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.589:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.597:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.598:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.612:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.613:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.614:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.663:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.696:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.723:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.839:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.572:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.588:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.700:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.701:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.717:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.236:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sidefind : Cleaned.
:mozilla.240:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[2].txt -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[3].txt -> TrackingCookie.Sidefind : Cleaned.
:mozilla.841:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.842:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.843:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.47:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.54:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.55:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.56:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.57:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.58:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.622:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@spylog[1].txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.704:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.705:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.706:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.707:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.708:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.709:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.617:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.623:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.375:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.386:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.387:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.388:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@tradedoubler[4].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.503:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.504:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.408:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.536:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.542:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@pr.valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.434:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.46:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.49:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.50:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.51:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.52:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.53:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@wreport.weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.571:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.776:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.777:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.113:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.121:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.122:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.123:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Tu peut me dire quesque je doit faire a présent? Merci
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 21:43:49 26/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : Cleaned.
HKU\S-1-5-21-1644491937-839522115-682003330-1004\Software\Internet Security -> Adware.IntCodec : Cleaned.
C:\Documents and Settings\TEMP\Local Settings\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\Cache\6F4BFF4Ad01 -> Not-A-Virus.Downloader.Win32.WinFixer.m : Cleaned.
:mozilla.63:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.64:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.578:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.870:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.874:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.884:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.886:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.939:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.847:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.882:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.890:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.945:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.791:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.792:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.849:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.38:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.84:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.59:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads13.bpath[1].txt -> TrackingCookie.Bpath : Cleaned.
:mozilla.365:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@casinotropez[1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bilbo.counted[2].txt -> TrackingCookie.Counted : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.45:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.28:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.347:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-nestlefr.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ehg-sonyesolutions.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.575:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.626:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.867:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.29:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.30:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads.planetactive[2].txt -> TrackingCookie.Planetactive : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.799:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.800:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.801:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.564:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.586:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.589:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.597:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.598:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.612:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.613:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.614:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.663:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.696:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.723:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.839:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.572:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.588:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.700:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.701:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.717:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.236:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sidefind : Cleaned.
:mozilla.240:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[2].txt -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[3].txt -> TrackingCookie.Sidefind : Cleaned.
:mozilla.841:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.842:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.843:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.47:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.54:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.55:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.56:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.57:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.58:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.622:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@spylog[1].txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.704:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.705:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.706:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.707:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.708:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.709:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.617:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.623:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.375:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.386:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.387:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.388:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@tradedoubler[4].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.503:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.504:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.408:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.536:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.542:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@pr.valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.434:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.46:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.49:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.50:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.51:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.52:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.53:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@wreport.weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.571:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.776:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.777:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.113:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.121:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.122:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.123:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\8372ndbq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\TEMP\Cookies\maison@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\maison\Cookies\maison@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Tu peut me dire quesque je doit faire a présent? Merci
Salut,
maintenant fait ça
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
et
Télécharges Blacklight et sauvegarde le sur ton bureau.
https://www.f-secure.com/en
Double cliques sur " blbeta.exe " et acceptes la licence; clic sur "Scan" puis "Next"
Un rapport, va se créer sur ton bureau "fslb-....."
Copies et colles le contenu de ce rapport ici.
Ne touche à rien d'autre!
maintenant fait ça
Fait ce nettoyage: (à faire réguliérement)
¤Telecharges et installes ceci:
CCleaner:
Ccleaner
dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes
¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"
et
Télécharges Blacklight et sauvegarde le sur ton bureau.
https://www.f-secure.com/en
Double cliques sur " blbeta.exe " et acceptes la licence; clic sur "Scan" puis "Next"
Un rapport, va se créer sur ton bureau "fslb-....."
Copies et colles le contenu de ce rapport ici.
Ne touche à rien d'autre!
Je croit qu'il y a un petit probléme par rapport a Ccleaner, j'ai fait le scan plus de 20 fois, et il revient toujours le même seul et unique probléme "Police inexistante - Box alphabe?() - HKLM\Software\Microsoft\Windows NT\Current Version\Fonts
Et voici le rapport de Blacklight :
10/27/06 10:40:08 [Info]: BlackLight Engine 1.0.47 initialized
10/27/06 10:40:08 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/27/06 10:40:08 [Note]: 7019 4
10/27/06 10:40:08 [Note]: 7005 0
10/27/06 10:40:10 [Note]: 7006 0
10/27/06 10:40:10 [Note]: 7011 368
10/27/06 10:40:10 [Note]: 7026 0
10/27/06 10:40:10 [Note]: 7026 0
10/27/06 10:40:15 [Note]: FSRAW library version 1.7.1020
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:43:50 [Note]: 7007 0
Et voici le rapport de Blacklight :
10/27/06 10:40:08 [Info]: BlackLight Engine 1.0.47 initialized
10/27/06 10:40:08 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/27/06 10:40:08 [Note]: 7019 4
10/27/06 10:40:08 [Note]: 7005 0
10/27/06 10:40:10 [Note]: 7006 0
10/27/06 10:40:10 [Note]: 7011 368
10/27/06 10:40:10 [Note]: 7026 0
10/27/06 10:40:10 [Note]: 7026 0
10/27/06 10:40:15 [Note]: FSRAW library version 1.7.1020
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:42:31 [Note]: 2000 1012
10/27/06 10:43:50 [Note]: 7007 0
Ccleaner te signale juste qu'apparement il te manque une Police décriture dans Windows
Rien d'alarmant ! tu peux en ajouter d'autres, mais ça ne sert à rien si tu ne les utilise pas ;-)
ça me semble propre ou en est ton ton problème ?
Rien d'alarmant ! tu peux en ajouter d'autres, mais ça ne sert à rien si tu ne les utilise pas ;-)
ça me semble propre ou en est ton ton problème ?
Merci, mais mon probléme est toujours présent.
Lorsque je lance Internet Explorer, au lieu de me lancer sur ma page d'acceuil habituelle, sa m'envoie sur un site, me disant que j'ai un probléme de virus. Et une fenétre s'éffiche, elle sit sa:
Warning!
W32.Pysor.FK@yf is a virus that infects files with .exe extensions. It attempts to steal passwords and privates information from the infected computer.
Type: Virus
Infection Length : 138,293 bytes
Systems Affected: Windows 95, 98, ME, NT (all versions), 2003, Windows Xp (all service packs)
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical details : 1. Creates files in %Windir%\ directory. By default, this is c:\Windows.
2. Adds values to registry keys: HKEY_LOCAL_MNACHINE\Software\Microsoft\Windows\CurrentVersion\Run
3. Scans the hard drive for .exe files and infects any executable files.
Searches for passwords/information, whiwh it may send to a remote attacker.
Recomendations : Clik "OK" to download officially approved security software. Always keep your patch levels up-to-date.
Case "OK" - Case "Annuler"
Et puis j'ai toujours le triangle jaune clignotant qui s'affiche de temps en temps, avec des message d'erreur. Des fenétres qui s'ouvrent seuls (pop-up je pense) et qui m'invitent a acheter des antivirus et autre.
Et j'ai également constater que mon ordinateur est un peu moins rapide depuis ce matin, il est long a afficher les page web, à ouvrir mes document,...
Tu pense que sa vient de quoi?
Lorsque je lance Internet Explorer, au lieu de me lancer sur ma page d'acceuil habituelle, sa m'envoie sur un site, me disant que j'ai un probléme de virus. Et une fenétre s'éffiche, elle sit sa:
Warning!
W32.Pysor.FK@yf is a virus that infects files with .exe extensions. It attempts to steal passwords and privates information from the infected computer.
Type: Virus
Infection Length : 138,293 bytes
Systems Affected: Windows 95, 98, ME, NT (all versions), 2003, Windows Xp (all service packs)
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical details : 1. Creates files in %Windir%\ directory. By default, this is c:\Windows.
2. Adds values to registry keys: HKEY_LOCAL_MNACHINE\Software\Microsoft\Windows\CurrentVersion\Run
3. Scans the hard drive for .exe files and infects any executable files.
Searches for passwords/information, whiwh it may send to a remote attacker.
Recomendations : Clik "OK" to download officially approved security software. Always keep your patch levels up-to-date.
Case "OK" - Case "Annuler"
Et puis j'ai toujours le triangle jaune clignotant qui s'affiche de temps en temps, avec des message d'erreur. Des fenétres qui s'ouvrent seuls (pop-up je pense) et qui m'invitent a acheter des antivirus et autre.
Et j'ai également constater que mon ordinateur est un peu moins rapide depuis ce matin, il est long a afficher les page web, à ouvrir mes document,...
Tu pense que sa vient de quoi?
fait un clic droit sur HijackThis, choisis "renomer" efface le texte puis mets celui la " acbde " puis 'ok'
Ensuite, remet un rapport hijackthis stp
Ensuite, remet un rapport hijackthis stp
Voila le rapport.
Logfile of HijackThis v1.99.1
Scan saved at 18:28:49, on 27/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\TrueCodec\pmsngr.exe
C:\Program Files\TrueCodec\pmmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\TEMP\Bureau\acbde.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 18:28:49, on 27/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\TrueCodec\pmsngr.exe
C:\Program Files\TrueCodec\pmmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\TEMP\Bureau\acbde.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
--O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
Clic sur "demarrer", "executer", tape: services.msc ,cherche dans la liste cette ligne, fais un clic droit dessus choisis "propriétés" et régle la sur "désactivé"
ewido anti-spyware 4.0 guard
Clic sur démarrer, poste de travail, C:, program files cherche et supprime ces dossiers:
MSN Apps
TrueCodec < saloprie
**Si un fichier persiste lors de la suppression fait ceci:
-Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement
Télécharge SmitfraudFix (enregistre le sur le "bureau")
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
décompresse SmitfraudFix
Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7b4d79df-9ef0-429d-a0e9-d9b138c6a53b} - C:\Program Files\TrueCodec\isaddon.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OFFICE One 6.5.lnk = C:\Program Files\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
--O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - http://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
Clic sur "demarrer", "executer", tape: services.msc ,cherche dans la liste cette ligne, fais un clic droit dessus choisis "propriétés" et régle la sur "désactivé"
ewido anti-spyware 4.0 guard
Clic sur démarrer, poste de travail, C:, program files cherche et supprime ces dossiers:
MSN Apps
TrueCodec < saloprie
**Si un fichier persiste lors de la suppression fait ceci:
-Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement
Télécharge SmitfraudFix (enregistre le sur le "bureau")
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
décompresse SmitfraudFix
Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp
C'est bon, j'ai pu suprimer MSN Apps, et True Codec (en utilisant le mode sans échec).
Et voici le rapport de SmitfraudFix :
SmitFraudFix v2.114
Rapport fait à 22:10:13,42, 27/10/2006
Executé à partir de C:\Program Files\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TEMP
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TEMP\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\TEMP\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="sockspy.dll"
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Et voici le rapport de SmitfraudFix :
SmitFraudFix v2.114
Rapport fait à 22:10:13,42, 27/10/2006
Executé à partir de C:\Program Files\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TEMP
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TEMP\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\TEMP\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="sockspy.dll"
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Salut,
c'est bon tu peux jeter SmitFraudFix
Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
Une fois qu'il a terminé colle le rapport ici stp
_Online Scanner
_Kaspersky Online Scanner
_My Computer
https://www.kaspersky.fr/downloads
A++
c'est bon tu peux jeter SmitFraudFix
Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
Une fois qu'il a terminé colle le rapport ici stp
_Online Scanner
_Kaspersky Online Scanner
_My Computer
https://www.kaspersky.fr/downloads
A++
Salut, javai le même problème que Marc06 et g feinté le virus :p
En fait j'ai fait le gestionnaire des tacheset g supprimé l'application du virus "pnmsgr".
Ensuite, j'ai été virer le virus tant kil "bougeai" plu pendant kil se préparait a revenir :p
il se situe dans C:/progammes files/video active X
Depuis j'ai plus aucun embêtement.
Tchô
En fait j'ai fait le gestionnaire des tacheset g supprimé l'application du virus "pnmsgr".
Ensuite, j'ai été virer le virus tant kil "bougeai" plu pendant kil se préparait a revenir :p
il se situe dans C:/progammes files/video active X
Depuis j'ai plus aucun embêtement.
Tchô
Bonjour,
DEpuis quelque temps j'ai un souci avec mon ordinateur. la taille de la police a changé les lettres sont devenus grosses et quand je navigue sur internet les pages défilent très lentement.
j'ai aussi le triangle jaune m'alertant que je suis infecté d'un virus psw.x-vir trojan
d'autre message apparaissent aussi, comme malware threats ou networm-l.virus@fp, spyware.cyber.cyberlog-x, system performance monitor: warning ....
voilà ce que me donne hidjack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:35:03, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {ca7048b4-c29a-bd78-b8f4-0948dbee8581} - {1858eebd-8490-4f8b-87db-a92c4b8407ac} - C:\WINDOWS\system32\twcmqmrt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\lfpwofhj.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FShow - {F28ED85C-A8AE-4e69-B92E-6279C02010DC} - C:\Program Files\FShow\win-browser.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\lfpwofhj.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O20 - Winlogon Notify: lfpwofhj - C:\WINDOWS\SYSTEM32\lfpwofhj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
DEpuis quelque temps j'ai un souci avec mon ordinateur. la taille de la police a changé les lettres sont devenus grosses et quand je navigue sur internet les pages défilent très lentement.
j'ai aussi le triangle jaune m'alertant que je suis infecté d'un virus psw.x-vir trojan
d'autre message apparaissent aussi, comme malware threats ou networm-l.virus@fp, spyware.cyber.cyberlog-x, system performance monitor: warning ....
voilà ce que me donne hidjack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:35:03, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {ca7048b4-c29a-bd78-b8f4-0948dbee8581} - {1858eebd-8490-4f8b-87db-a92c4b8407ac} - C:\WINDOWS\system32\twcmqmrt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\lfpwofhj.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FShow - {F28ED85C-A8AE-4e69-B92E-6279C02010DC} - C:\Program Files\FShow\win-browser.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\lfpwofhj.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide1] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O20 - Winlogon Notify: lfpwofhj - C:\WINDOWS\SYSTEM32\lfpwofhj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Attention, il semblerais que toutes ces installation soit inutile. le seul virus dont est vraiment infecter ton/vos PC EST le soit-disant Anti-virus. NE VOUS FAITES PAS AVOIR! IL NA R-I-E-N DÉTECTER SUR VOTRE PC
Ce virus est installer par le site de l'anti-virus et tente de vous forcer a acheter l'anti-virus en question aussi ne vous faites pas avoir! C'est de l'escroquerie pure et dure! (pour la métaphore, c'est comme si un garagiste coupait vos tuyau de freins pour pouvoir refaire la peinture de votre voiture)
Ce virus est installer par le site de l'anti-virus et tente de vous forcer a acheter l'anti-virus en question aussi ne vous faites pas avoir! C'est de l'escroquerie pure et dure! (pour la métaphore, c'est comme si un garagiste coupait vos tuyau de freins pour pouvoir refaire la peinture de votre voiture)
Je cite
Alors, aprés une recherche rapide, le nom exacte est sbmntr.exe et il semblerais qui plus est que le site est une arnaque. si vous tombez sur une alerte comprenant "malware threats" ou arrivez sur une page internet nommée spy-shredder, virus-ranger, (il y en a une disaine d'autre) il sagit du dit site créé par les dit connard (pardon ça ma échapper...)
Bref, apparament le logiciel qui force votre PC a agir ainsi et laisse passer les pop-up se trouve à l'emplacement suivant:
C://program files/NetProject. il semblerais que détruire le fichier suffit. Je m'auto-infecte actuelement pour vous donner les nouvelles du front
Salut, javai le même problème que Marc06 et g feinté le virus :p En fait j'ai fait le gestionnaire des tacheset g supprimé l'application du virus "pnmsgr". Ensuite, j'ai été virer le virus tant kil "bougeai" plu pendant kil se préparait a revenir :p il se situe dans C:/progammes files/video active X Depuis j'ai plus aucun embêtement. Tchô(Cousteau86)
Alors, aprés une recherche rapide, le nom exacte est sbmntr.exe et il semblerais qui plus est que le site est une arnaque. si vous tombez sur une alerte comprenant "malware threats" ou arrivez sur une page internet nommée spy-shredder, virus-ranger, (il y en a une disaine d'autre) il sagit du dit site créé par les dit connard (pardon ça ma échapper...)
Bref, apparament le logiciel qui force votre PC a agir ainsi et laisse passer les pop-up se trouve à l'emplacement suivant:
C://program files/NetProject. il semblerais que détruire le fichier suffit. Je m'auto-infecte actuelement pour vous donner les nouvelles du front
bonjour j'ai le même problème en quelque sorte voila les résultat de hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 07:37:06, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\sbsm.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\wksmgrtsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Patrick\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: 215651 helper - {0BC5E8C9-6EFF-4976-9A3C-D74148442CE7} - C:\WINDOWS\system32\215651\215651.dll
O2 - BHO: (no name) - {304A642D-F1D5-4C89-879E-0DAB7E4D397E} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {77653f90-818f-870a-9fa4-02cc6943171e} - {e1713496-cc20-4af9-a078-f81809f35677} - C:\WINDOWS\system32\aideuowp.dll (file missing)
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\Helper\turbosearchsite.dll (file missing)
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [000a222a] rundll32.exe "C:\WINDOWS\system32\nbhkylkt.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Control Server] wksmgrtsgs.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [E06FXLRD_2613437] "C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Download with &FileFactory Turbo - C:\Program Files\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: logiciels - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra button: private access - {2B44FD33-B048-4B2B-88D5-4B80AB018F29} - C:\WINDOWS\system32\private access (file missing)
O9 - Extra button: 123MP3FR - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\123MP3FR (file missing)
O9 - Extra button: logiciels - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\logiciels (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: musique - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: musique - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\musique (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: private access - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX 5.5 Basic) - https://fedhub.airfrance.fr/idp/eyJ2c2lkIjoidXJuOmlkcDpwcmQ6YWZyOnBmOmRtemk6c3Ryb25nIn0/SSO.saml2?SAMLRequest=lZJfT8IwFMXf%2BRRL39lK2UAaWILwAtEQN%2BMfXkzXtaGydrO3i%2BCnd8NFeUAT%2B9CHm9Nzfvek03ntdiYRb7UA5y2bSxnmVGlmaOdcBTQIpMh3deYzZaVlhgtf2kDlVSCOa8JJsV%2B9lip%2FWtcbXez5snrn%2Bm70%2FLg9bsy13ujECb0f8WFyzEhkVgYHabrxgemCIG%2B1nKGXHMuJGMswHIXZOCLyaiwyOQ7lALOQ4OEoI5NWClCLlQHHjJshggnuY9LH0f0gomFEB3iLvAdh4YROfIy8gy4MzFBtDS0ZKKCGaQHUcZrOb29oo6GVLV3JywLFPa85UwMDegqyX69pM%2FjbgQEI2%2FaF4lYGVeOZUyYtBU1z%2FaGmwY9pl9K1LfJT94vSOHFw3qLUFbMKWn6tjNK17rA6NELP9YuiiU6E%2FAYl%2FwL9VcYpb52bcZLOW%2FjLsd0qwcVd4t40OP9X8Sc%3D&RelayState=ec3e66c8d180e19635c513ef5242ac86130a17e8&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=dNr%2BNf29qSinhbIDnSqHW63MlQUvrQqwGtkSLoZXUEg96%2FQAwHyuSfsgfzpg6AOjWGMKbBaDDmXlgl5uR%2FxTvbzJuJe%2FTmDfT95uXikIfK5lfieXSYZfE7%2FUBq%2FGsfDvCrBqaEoWeXzjgoCycyPCPU82fXHVDkY%2BHBs22hnlxA0kCZ2yD2BvzfXaI7G0fITIujKMgLjaaFkUhTJ0%2BSBI2z1Zh8F%2BiU9d0MfmF%2F2D2Y8Aan%2F5Mi%2FTAXryQhlUUE8cZkXj
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://alexleleopardalex1995.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7C6E92FA-4429-4FB6-909B-798E2EFFAEF0} (NCWeb.Launcher) - https://lineage2.plaync.com
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\system32\nodeipproc.dll (file missing)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: iifcbcc - iifcbcc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sgdmntrq.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
reponder moi vite svp
Logfile of HijackThis v1.99.1
Scan saved at 07:37:06, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\sbsm.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\wksmgrtsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Patrick\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: 215651 helper - {0BC5E8C9-6EFF-4976-9A3C-D74148442CE7} - C:\WINDOWS\system32\215651\215651.dll
O2 - BHO: (no name) - {304A642D-F1D5-4C89-879E-0DAB7E4D397E} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {77653f90-818f-870a-9fa4-02cc6943171e} - {e1713496-cc20-4af9-a078-f81809f35677} - C:\WINDOWS\system32\aideuowp.dll (file missing)
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\Helper\turbosearchsite.dll (file missing)
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [000a222a] rundll32.exe "C:\WINDOWS\system32\nbhkylkt.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Control Server] wksmgrtsgs.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [E06FXLRD_2613437] "C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Download with &FileFactory Turbo - C:\Program Files\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: logiciels - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra button: private access - {2B44FD33-B048-4B2B-88D5-4B80AB018F29} - C:\WINDOWS\system32\private access (file missing)
O9 - Extra button: 123MP3FR - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\123MP3FR (file missing)
O9 - Extra button: logiciels - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\logiciels (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: musique - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: musique - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\musique (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: private access - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX 5.5 Basic) - https://fedhub.airfrance.fr/idp/eyJ2c2lkIjoidXJuOmlkcDpwcmQ6YWZyOnBmOmRtemk6c3Ryb25nIn0/SSO.saml2?SAMLRequest=lZJfT8IwFMXf%2BRRL39lK2UAaWILwAtEQN%2BMfXkzXtaGydrO3i%2BCnd8NFeUAT%2B9CHm9Nzfvek03ntdiYRb7UA5y2bSxnmVGlmaOdcBTQIpMh3deYzZaVlhgtf2kDlVSCOa8JJsV%2B9lip%2FWtcbXez5snrn%2Bm70%2FLg9bsy13ujECb0f8WFyzEhkVgYHabrxgemCIG%2B1nKGXHMuJGMswHIXZOCLyaiwyOQ7lALOQ4OEoI5NWClCLlQHHjJshggnuY9LH0f0gomFEB3iLvAdh4YROfIy8gy4MzFBtDS0ZKKCGaQHUcZrOb29oo6GVLV3JywLFPa85UwMDegqyX69pM%2FjbgQEI2%2FaF4lYGVeOZUyYtBU1z%2FaGmwY9pl9K1LfJT94vSOHFw3qLUFbMKWn6tjNK17rA6NELP9YuiiU6E%2FAYl%2FwL9VcYpb52bcZLOW%2FjLsd0qwcVd4t40OP9X8Sc%3D&RelayState=ec3e66c8d180e19635c513ef5242ac86130a17e8&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=dNr%2BNf29qSinhbIDnSqHW63MlQUvrQqwGtkSLoZXUEg96%2FQAwHyuSfsgfzpg6AOjWGMKbBaDDmXlgl5uR%2FxTvbzJuJe%2FTmDfT95uXikIfK5lfieXSYZfE7%2FUBq%2FGsfDvCrBqaEoWeXzjgoCycyPCPU82fXHVDkY%2BHBs22hnlxA0kCZ2yD2BvzfXaI7G0fITIujKMgLjaaFkUhTJ0%2BSBI2z1Zh8F%2BiU9d0MfmF%2F2D2Y8Aan%2F5Mi%2FTAXryQhlUUE8cZkXj
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://alexleleopardalex1995.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7C6E92FA-4429-4FB6-909B-798E2EFFAEF0} (NCWeb.Launcher) - https://lineage2.plaync.com
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\system32\nodeipproc.dll (file missing)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: iifcbcc - iifcbcc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sgdmntrq.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
reponder moi vite svp
mon probleme est dit dans le sujet merci de m'aider
resulat hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 07:37:06, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\sbsm.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\wksmgrtsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Patrick\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: 215651 helper - {0BC5E8C9-6EFF-4976-9A3C-D74148442CE7} - C:\WINDOWS\system32\215651\215651.dll
O2 - BHO: (no name) - {304A642D-F1D5-4C89-879E-0DAB7E4D397E} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {77653f90-818f-870a-9fa4-02cc6943171e} - {e1713496-cc20-4af9-a078-f81809f35677} - C:\WINDOWS\system32\aideuowp.dll (file missing)
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\Helper\turbosearchsite.dll (file missing)
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [000a222a] rundll32.exe "C:\WINDOWS\system32\nbhkylkt.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Control Server] wksmgrtsgs.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [E06FXLRD_2613437] "C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Download with &FileFactory Turbo - C:\Program Files\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: logiciels - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra button: private access - {2B44FD33-B048-4B2B-88D5-4B80AB018F29} - C:\WINDOWS\system32\private access (file missing)
O9 - Extra button: 123MP3FR - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\123MP3FR (file missing)
O9 - Extra button: logiciels - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\logiciels (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: musique - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: musique - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\musique (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: private access - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX 5.5 Basic) - https://fedhub.airfrance.fr/idp/eyJ2c2lkIjoidXJuOmlkcDpwcmQ6YWZyOnBmOmRtemk6c3Ryb25nIn0/SSO.saml2?SAMLRequest=lZJfT8IwFMXf%2BRRL39lK2UAaWILwAtEQN%2BMfXkzXtaGydrO3i%2BCnd8NFeUAT%2B9CHm9Nzfvek03ntdiYRb7UA5y2bSxnmVGlmaOdcBTQIpMh3deYzZaVlhgtf2kDlVSCOa8JJsV%2B9lip%2FWtcbXez5snrn%2Bm70%2FLg9bsy13ujECb0f8WFyzEhkVgYHabrxgemCIG%2B1nKGXHMuJGMswHIXZOCLyaiwyOQ7lALOQ4OEoI5NWClCLlQHHjJshggnuY9LH0f0gomFEB3iLvAdh4YROfIy8gy4MzFBtDS0ZKKCGaQHUcZrOb29oo6GVLV3JywLFPa85UwMDegqyX69pM%2FjbgQEI2%2FaF4lYGVeOZUyYtBU1z%2FaGmwY9pl9K1LfJT94vSOHFw3qLUFbMKWn6tjNK17rA6NELP9YuiiU6E%2FAYl%2FwL9VcYpb52bcZLOW%2FjLsd0qwcVd4t40OP9X8Sc%3D&RelayState=ec3e66c8d180e19635c513ef5242ac86130a17e8&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=dNr%2BNf29qSinhbIDnSqHW63MlQUvrQqwGtkSLoZXUEg96%2FQAwHyuSfsgfzpg6AOjWGMKbBaDDmXlgl5uR%2FxTvbzJuJe%2FTmDfT95uXikIfK5lfieXSYZfE7%2FUBq%2FGsfDvCrBqaEoWeXzjgoCycyPCPU82fXHVDkY%2BHBs22hnlxA0kCZ2yD2BvzfXaI7G0fITIujKMgLjaaFkUhTJ0%2BSBI2z1Zh8F%2BiU9d0MfmF%2F2D2Y8Aan%2F5Mi%2FTAXryQhlUUE8cZkXj
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://alexleleopardalex1995.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7C6E92FA-4429-4FB6-909B-798E2EFFAEF0} (NCWeb.Launcher) - https://lineage2.plaync.com
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\system32\nodeipproc.dll (file missing)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: iifcbcc - iifcbcc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sgdmntrq.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
resulat hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 07:37:06, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\sbsm.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\wksmgrtsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Patrick\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: 215651 helper - {0BC5E8C9-6EFF-4976-9A3C-D74148442CE7} - C:\WINDOWS\system32\215651\215651.dll
O2 - BHO: (no name) - {304A642D-F1D5-4C89-879E-0DAB7E4D397E} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {77653f90-818f-870a-9fa4-02cc6943171e} - {e1713496-cc20-4af9-a078-f81809f35677} - C:\WINDOWS\system32\aideuowp.dll (file missing)
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Program Files\Helper\turbosearchsite.dll (file missing)
O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [000a222a] rundll32.exe "C:\WINDOWS\system32\nbhkylkt.dll",b
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Control Server] wksmgrtsgs.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [E06FXLRD_2613437] "C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: Download with &FileFactory Turbo - C:\Program Files\FileFactory Turbo\Plugins\IE\FileFactoryIE.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: logiciels - {16930DCA-0910-4C00-86FF-0C73872D4ABA} - javascript:window.location.href="http://www.download-plus.com/fr/emule/default.asp?id=" (file missing)
O9 - Extra button: private access - {2B44FD33-B048-4B2B-88D5-4B80AB018F29} - C:\WINDOWS\system32\private access (file missing)
O9 - Extra button: 123MP3FR - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\system32\123MP3FR (file missing)
O9 - Extra button: logiciels - {810B72CB-566A-409B-B6A3-31F720C16FAE} - C:\WINDOWS\system32\logiciels (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ieservicegate.com/redirect.php (file missing)
O9 - Extra button: (no name) - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: musique - {A2199168-22AC-44A3-BA5F-8A83E693FEBF} - javascript:window.location.href="http://www.webmp3musique.com/fr/default.asp?id=" (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: musique - {F4445FEB-6D20-47CB-9ACF-9D142A7F680A} - C:\WINDOWS\system32\musique (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra 'Tools' menuitem: private access - {FF55FC7B-F2EB-4F50-9409-2F726DD0E112} - javascript:window.location.href="http://www.morefreenudes.com/default.asp?id=" (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX 5.5 Basic) - https://fedhub.airfrance.fr/idp/eyJ2c2lkIjoidXJuOmlkcDpwcmQ6YWZyOnBmOmRtemk6c3Ryb25nIn0/SSO.saml2?SAMLRequest=lZJfT8IwFMXf%2BRRL39lK2UAaWILwAtEQN%2BMfXkzXtaGydrO3i%2BCnd8NFeUAT%2B9CHm9Nzfvek03ntdiYRb7UA5y2bSxnmVGlmaOdcBTQIpMh3deYzZaVlhgtf2kDlVSCOa8JJsV%2B9lip%2FWtcbXez5snrn%2Bm70%2FLg9bsy13ujECb0f8WFyzEhkVgYHabrxgemCIG%2B1nKGXHMuJGMswHIXZOCLyaiwyOQ7lALOQ4OEoI5NWClCLlQHHjJshggnuY9LH0f0gomFEB3iLvAdh4YROfIy8gy4MzFBtDS0ZKKCGaQHUcZrOb29oo6GVLV3JywLFPa85UwMDegqyX69pM%2FjbgQEI2%2FaF4lYGVeOZUyYtBU1z%2FaGmwY9pl9K1LfJT94vSOHFw3qLUFbMKWn6tjNK17rA6NELP9YuiiU6E%2FAYl%2FwL9VcYpb52bcZLOW%2FjLsd0qwcVd4t40OP9X8Sc%3D&RelayState=ec3e66c8d180e19635c513ef5242ac86130a17e8&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=dNr%2BNf29qSinhbIDnSqHW63MlQUvrQqwGtkSLoZXUEg96%2FQAwHyuSfsgfzpg6AOjWGMKbBaDDmXlgl5uR%2FxTvbzJuJe%2FTmDfT95uXikIfK5lfieXSYZfE7%2FUBq%2FGsfDvCrBqaEoWeXzjgoCycyPCPU82fXHVDkY%2BHBs22hnlxA0kCZ2yD2BvzfXaI7G0fITIujKMgLjaaFkUhTJ0%2BSBI2z1Zh8F%2BiU9d0MfmF%2F2D2Y8Aan%2F5Mi%2FTAXryQhlUUE8cZkXj
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://alexleleopardalex1995.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7C6E92FA-4429-4FB6-909B-798E2EFFAEF0} (NCWeb.Launcher) - https://lineage2.plaync.com
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\system32\nodeipproc.dll (file missing)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: iifcbcc - iifcbcc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\sgdmntrq.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Voici le rapport :
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 14:54:04 26/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historyfiles -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\YourSiteBar\Historysearch_term -> Adware.ISTBar : No action taken.
HKLM\SOFTWARE\PowerScan -> Adware.PowerScan : No action taken.
C:\Program Files\SideFind -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_f_b_h_o_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\__delete_on_reboot__s_i_d_e_f_i_n_d_._d_l_l_ -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\sfexd001 -> Adware.SideFind : No action taken.
C:\Program Files\SideFind\update -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\BrowserHelperObject.BAHelper -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\BrowserHelperObject.BAHelper.1 -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\BrowserHelperObject.BAHelper\CLSID -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\BrowserHelperObject.BAHelper\CurVer -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\SideFind.Finder -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\SideFind.Finder.1 -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\SideFind.Finder\CLSID -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Classes\SideFind.Finder\CurVer -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\Microsoft\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind -> Adware.SideFind : No action taken.
HKLM\SOFTWARE\SideFind\History -> Adware.SideFind : No action taken.
[1672] C:\Program Files\SideFind\sfbho.dll -> Adware.SideFind : No action taken.
[7968] C:\Program Files\SideFind\sfbho.dll -> Adware.SideFind : No action taken.
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\License.lnk -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\SurfAccuracy\__delete_on_reboot__S_A_c_c_._e_x_e_ -> Adware.SurfAccuracy : No action taken.
C:\WINDOWS\vweksplo.exe -> Adware.SurfAccuracy : No action taken.
C:\Program Files\Fichiers communs\WinSoftware\CrXML.dll -> Adware.Winfixer : No action taken.
C:\Program Files\YourSiteBar -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\imagemap_normal.bmp -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\version.txt -> Adware.YourSiteBar : No action taken.
C:\Program Files\YourSiteBar\yoursitebar.xml -> Adware.YourSiteBar : No action taken.
HKLM\SOFTWARE\Classes\Ysb.YsbObj -> Adware.YourSiteBar : No action taken.
HKLM\SOFTWARE\Classes\Ysb.YsbObj.1 -> Adware.YourSiteBar : No action taken.
HKLM\SOFTWARE\Classes\Ysb.YsbObj\CLSID -> Adware.YourSiteBar : No action taken.
HKLM\SOFTWARE\Classes\Ysb.YsbObj\CurVer -> Adware.YourSiteBar : No action taken.
C:\Documents and Settings\TEMP\Local Settings\Temporary Internet Files\Content.IE5\8T6NKP63\SystemDoctor2006FreeInstall_fr[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : No action taken.
C:\WINDOWS\system32\drivers\df_kmd.sys -> Rootkit.Agent.af : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@112.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@boonty.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@gettyimages.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\maison\Cookies\maison@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adjuggler[2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\maison\Cookies\maison@servedby.advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\maison\Cookies\maison@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bfast[2].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bfast[1].txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads13.bpath[1].txt -> TrackingCookie.Bpath : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : No action taken.
C:\Documents and Settings\maison\Cookies\maison@casinotropez[1].txt -> TrackingCookie.Casinotropez : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.clubdicecasino[1].txt -> TrackingCookie.Clubdicecasino : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bilbo.counted[2].txt -> TrackingCookie.Counted : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\maison\Cookies\maison@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as-eu.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\maison\Cookies\maison@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-adteractive.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-bluesouth.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-foxmovies.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-hitent.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-mybc.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-netquote.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-nokiafin.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-ogilvy.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ehg-yvesrocher.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nestlefr.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-nokiafin.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ehg-sonyesolutions.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\maison\Cookies\maison@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@hotlog[1].txt -> TrackingCookie.Hotlog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@sales.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\maison\Cookies\maison@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\maison\Cookies\maison@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.planetactive[2].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\maison\Cookies\maison@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\maison\Cookies\maison@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\maison\Cookies\maison@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\maison\Cookies\maison@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.sidefind[1].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[2].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.sidefind[3].txt -> TrackingCookie.Sidefind : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\maison\Cookies\maison@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@spylog[1].txt -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@anad.tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\maison\Cookies\maison@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tradedoubler[4].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\maison\Cookies\maison@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@pr.valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\maison\Cookies\maison@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\maison\Cookies\maison@wreport.weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\maison\Cookies\maison@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\maison\Cookies\maison@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\TEMP\Cookies\maison@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\maison\Cookies\maison@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
::Report end