Infected by I-worm/brontok.C
Solved
bertha
-
green day Posted messages 26374 Registration date Status Modérateur, Contributeur sécurité Last intervention -
green day Posted messages 26374 Registration date Status Modérateur, Contributeur sécurité Last intervention -
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Sorry, this GeoCities site is currently unavailable.
O1 - Hosts: The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later.
O1 - Hosts:Are you the site owner? O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit! O1 - Hosts: Find out how.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: SPONSORED LINKS
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Reliable plans include domain & 24x7 support.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Includes starter web page, email & domain forwarding, 24x7 support.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: $50 setup fee waived. A reliable ecommerce plan, 24x7 support.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Copyright © O1 - Hosts: 2005 Yahoo! Inc. All rights reserved
O1 - Hosts: Privacy Policy O1 - Hosts: - Copyright Policy O1 - Hosts: - Guidelines O1 - Hosts: - Terms of Service O1 - Hosts: - Help O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Copyright © O1 - Hosts: 2005 Yahoo! Inc. All rights reserved
O1 - Hosts: Privacy Policy O1 - Hosts: - Copyright Policy O1 - Hosts: - Guidelines O1 - Hosts: - Terms of Service O1 - Hosts: - Help O1 - Hosts:
23 réponses
- 1
- 2
Suivant
Oops! I just saw it :)
Please stay on the same thread!
Otherwise, we're going to get lost ;)
Open the file "C:\WINDOWS\system32\drivers\etc\hosts" with Notepad, delete all its content and paste the following text (in bold) in its place:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP
# for Windows.
#
# This file contains the mappings of IP addresses to host names.
# Each entry should be on a separate line. The IP address should be placed
# in the first column, followed by the corresponding host name. The
# IP address and the host name must be separated by at least one space.
#
# Additionally, comments (like this one) may be inserted on
# separate lines or after the computer name. They are indicated by the
# '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # client host x
127.0.0.1 localhost
Go to "File" > "Save", close everything and restart your PC
Then, do a "hijackthis" and post the new report with the results for your initial issue
Next, try to download AVG and run the scan in safe mode
Keep us updated, good luck, @+
**In truth, the path matters little, the will to arrive is all that matters (A. Camus)**
Please stay on the same thread!
Otherwise, we're going to get lost ;)
Open the file "C:\WINDOWS\system32\drivers\etc\hosts" with Notepad, delete all its content and paste the following text (in bold) in its place:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP
# for Windows.
#
# This file contains the mappings of IP addresses to host names.
# Each entry should be on a separate line. The IP address should be placed
# in the first column, followed by the corresponding host name. The
# IP address and the host name must be separated by at least one space.
#
# Additionally, comments (like this one) may be inserted on
# separate lines or after the computer name. They are indicated by the
# '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # client host x
127.0.0.1 localhost
Go to "File" > "Save", close everything and restart your PC
Then, do a "hijackthis" and post the new report with the results for your initial issue
Next, try to download AVG and run the scan in safe mode
Keep us updated, good luck, @+
**In truth, the path matters little, the will to arrive is all that matters (A. Camus)**
seen ;-)
@+
--
**In truth, the journey matters little, the will to arrive is enough for everything ( A.Camus ) **
@+
--
**In truth, the journey matters little, the will to arrive is enough for everything ( A.Camus ) **
Good evening, I've done what you both said, here’s the result
Is it better?
I still have my kesenjangan file at startup.
Well, I will scan with AVG to see. In any case, thanks again and greetings from Senegal where it’s terribly hot!
Bertha
Logfile of HijackThis v1.99.1
Scan saved at 00:31:06, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Quick startup of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quick launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Is it better?
I still have my kesenjangan file at startup.
Well, I will scan with AVG to see. In any case, thanks again and greetings from Senegal where it’s terribly hot!
Bertha
Logfile of HijackThis v1.99.1
Scan saved at 00:31:06, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Quick startup of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quick launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Hello you
Aww Did! You could have continued anyway ;-P
Bretha:
C:\windows\kesenjangansosial.exe. It asks me for it every time I start up. What is this file for?
To answer your question, yes it’s a nasty one! And you need to delete that bolded file!
Please do steps 1/ and 2/ from this link:
virus preliminary disinfection method version en
Catch you later
--
**In truth, the path matters little, the will to arrive is all that matters (A.Camus)**
Aww Did! You could have continued anyway ;-P
Bretha:
C:\windows\kesenjangansosial.exe. It asks me for it every time I start up. What is this file for?
To answer your question, yes it’s a nasty one! And you need to delete that bolded file!
Please do steps 1/ and 2/ from this link:
virus preliminary disinfection method version en
Catch you later
--
**In truth, the path matters little, the will to arrive is all that matters (A.Camus)**
Re
Hello Green D,
Here is the AVG analysis, I will do the scan with Bit Defender now
Thank you
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 15:59:36 16/11/2006
+ Scan results:
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006805.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006806.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006807.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006808.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006809.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).
End of report
Hello Green D,
Here is the AVG analysis, I will do the scan with Bit Defender now
Thank you
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 15:59:36 16/11/2006
+ Scan results:
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006805.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006806.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006807.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006808.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006809.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).
End of report
Hello Green Day,
here's the final report from BitDefender!!! OOPS I still had all this in there or did it scan what I had set in 40?
BitDefender Online Scanner
Scan report generated at: Thu, Nov 16, 2006 - 17:48:52
Scan path: C:\;D:\;E:\;
Statistics
Time
00:54:40
Files
515563
Folders
5176
Boot Sectors
4
Archives
8662
Packed Files
63672
Results
Identified Viruses
1
Infected Files
155
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
310
Engines Info
Virus Definitions
316345
Engine build
AVCORE v1.0 (build 2355) (i386) (Sep 25 2006 13:46:24)
Scan plugins
13
Archive plugins
38
Unpack plugins
6
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\chants
here's the final report from BitDefender!!! OOPS I still had all this in there or did it scan what I had set in 40?
BitDefender Online Scanner
Scan report generated at: Thu, Nov 16, 2006 - 17:48:52
Scan path: C:\;D:\;E:\;
Statistics
Time
00:54:40
Files
515563
Folders
5176
Boot Sectors
4
Archives
8662
Packed Files
63672
Results
Identified Viruses
1
Infected Files
155
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
310
Engines Info
Virus Definitions
316345
Engine build
AVCORE v1.0 (build 2355) (i386) (Sep 25 2006 13:46:24)
Scan plugins
13
Archive plugins
38
Unpack plugins
6
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Disinfection failed
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Deleted
C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\chants
Hi
all of this is the quarantine
please post a new hijackthis
++
--
**We can also build something beautiful with the stones that obstruct the path ( J.W.VON GOETH
)**
all of this is the quarantine
please post a new hijackthis
++
--
**We can also build something beautiful with the stones that obstruct the path ( J.W.VON GOETH
)**
Good evening Green Day, I (I completely understand your position)
here is the latest Hijack This report, soooo is it good? please tell me it's good !!!!
Bertha
Logfile of HijackThis v1.99.1
Scan saved at 22:58:51, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: HP Photosmart Premier Quick Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Reader Quick Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
here is the latest Hijack This report, soooo is it good? please tell me it's good !!!!
Bertha
Logfile of HijackThis v1.99.1
Scan saved at 22:58:51, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: HP Photosmart Premier Quick Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Reader Quick Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Good evening you,
sorry Green but I helped with the host file, then I prefer to let the first helper take care of it so as not to confuse things!
see you later
sorry Green but I helped with the host file, then I prefer to let the first helper take care of it so as not to confuse things!
see you later
Good evening Bertha!
We're almost there :-)
1) Show system folders and hidden files:
Open My Computer
- Tools --> Folder Options
- View --> Advanced settings
- Check: Show hidden files and folders
- Check: Show system files
- Uncheck: Hide extensions for known file types
- Uncheck: Hide protected operating system files (recommended)
Respond Yes to the message
Click on "Apply to all folders"
Click OK
2) Disable System Restore
* Click the Start button.
* Right-click on My Computer and then click on Properties.
* In the System Restore tab, select the option to Disable System Restore or Disable System Restore on all drives
(you can reactivate it at the end of the process)
3) Relaunch HijackThis: choose "do a scan only", check the box in front of the lines below and click "fix checked" at the bottom:
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a foreground tab - res://C:\Program Files\Windows Live
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
4) Search and delete the following bold files: (if present)
C:\WINDOWS\KesenjanganSosial.exe
C:\WINDOWS\ShellNew\RakyatKelaparan.exe
5) do this:
start==> run==> type: regedit
then by clicking on the +
follow this path
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_current_user... etc..
and delete DisableRegedit=1 by right-clicking on it and delete
6) download and run this:
* CleanUp40 (which eliminates temporary files + cookies: free)
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
tutorial: (thanks to Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm
* Ccleaner: Download and install this, in the left column click on "errors", check all the boxes, then click on "search for errors" at the bottom, once finished, click on "repair errors" and you will get a message to back up your registry, you say "yes" and then repeat until it finds no more errors.
* Relaunch Ccleaner, go to the "cleaner" tab on the left, uncheck the last box (Advanced if it
is checked) and then click on "run the cleaning"
ccleaner
tutorial: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
==> click on start < < run and type: Prefetch
and delete all the contents of this folder!
7) install a firewall:
kerio
tutorial: to configure and understand Kerio
https://www.vulgarisation-informatique.com/kerio.php
8) post a new hijackthis and specify your issues if any remain
don't hesitate to ask questions!
good luck, @+
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
We're almost there :-)
1) Show system folders and hidden files:
Open My Computer
- Tools --> Folder Options
- View --> Advanced settings
- Check: Show hidden files and folders
- Check: Show system files
- Uncheck: Hide extensions for known file types
- Uncheck: Hide protected operating system files (recommended)
Respond Yes to the message
Click on "Apply to all folders"
Click OK
2) Disable System Restore
* Click the Start button.
* Right-click on My Computer and then click on Properties.
* In the System Restore tab, select the option to Disable System Restore or Disable System Restore on all drives
(you can reactivate it at the end of the process)
3) Relaunch HijackThis: choose "do a scan only", check the box in front of the lines below and click "fix checked" at the bottom:
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a foreground tab - res://C:\Program Files\Windows Live
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
4) Search and delete the following bold files: (if present)
C:\WINDOWS\KesenjanganSosial.exe
C:\WINDOWS\ShellNew\RakyatKelaparan.exe
5) do this:
start==> run==> type: regedit
then by clicking on the +
follow this path
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_current_user... etc..
and delete DisableRegedit=1 by right-clicking on it and delete
6) download and run this:
* CleanUp40 (which eliminates temporary files + cookies: free)
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
tutorial: (thanks to Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm
* Ccleaner: Download and install this, in the left column click on "errors", check all the boxes, then click on "search for errors" at the bottom, once finished, click on "repair errors" and you will get a message to back up your registry, you say "yes" and then repeat until it finds no more errors.
* Relaunch Ccleaner, go to the "cleaner" tab on the left, uncheck the last box (Advanced if it
is checked) and then click on "run the cleaning"
ccleaner
tutorial: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
==> click on start < < run and type: Prefetch
and delete all the contents of this folder!
7) install a firewall:
kerio
tutorial: to configure and understand Kerio
https://www.vulgarisation-informatique.com/kerio.php
8) post a new hijackthis and specify your issues if any remain
don't hesitate to ask questions!
good luck, @+
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
Hi Green Day,
I was about to finally wrap things up with the instructions you gave me... but I don't understand why I can't find "folder options" in tools, in my computer, or even in the control panel under "appearance and themes." I don't have it. I don't have any problem on the other PC. It might be related to the fact that it's a Home XP and not Pro, as I said at the beginning. I got it wrong; it's the PC that's Pro, while the laptop is Home.
Or maybe I'm just really clueless... that could be it too.
I was about to finally wrap things up with the instructions you gave me... but I don't understand why I can't find "folder options" in tools, in my computer, or even in the control panel under "appearance and themes." I don't have it. I don't have any problem on the other PC. It might be related to the fact that it's a Home XP and not Pro, as I said at the beginning. I got it wrong; it's the PC that's Pro, while the laptop is Home.
Or maybe I'm just really clueless... that could be it too.
Hello Green Day, I did all the points except 1, 4, and 5 because I couldn't, a window opens with a message from the system administrator that blocks this action, and 7 because I haven't had the time yet.
Thank you GD
Logfile of HijackThis v1.99.1
Scan saved at 13:04:34, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\CleanUp!\cleanup.exe
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menu item: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Thank you GD
Logfile of HijackThis v1.99.1
Scan saved at 13:04:34, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\CleanUp!\cleanup.exe
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menu item: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Hi
you should have it! For XP Pro and Home, it's the same; the difference is not at that level...
window that opens with a message from the system administrator blocking this action,
do you have an administrator or limited rights session???
++
--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE)**
you should have it! For XP Pro and Home, it's the same; the difference is not at that level...
window that opens with a message from the system administrator blocking this action,
do you have an administrator or limited rights session???
++
--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE)**
Hi Green Day,
Ok Ok, I had to boot in safe mode and then log in as an administrator, but I didn't know that!!!!
So I did everything again.... I even "fixed checked" with HijackThis the lines I had deleted before.
Should I re-check and uncheck the lines in Folder Options now that I have finished the process?
Thank you so much for your patience and dedication... I have learned a lot but my eyes are glazed over. Here is the latest HijackThis. Otherwise, my scanner has been acting up since all these adjustments; it doesn't really recognize Word anymore, and displays weird symbols instead of font characters.
Logfile of HijackThis v1.99.1
Scan saved at 22:05:50, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
@+
Ok Ok, I had to boot in safe mode and then log in as an administrator, but I didn't know that!!!!
So I did everything again.... I even "fixed checked" with HijackThis the lines I had deleted before.
Should I re-check and uncheck the lines in Folder Options now that I have finished the process?
Thank you so much for your patience and dedication... I have learned a lot but my eyes are glazed over. Here is the latest HijackThis. Otherwise, my scanner has been acting up since all these adjustments; it doesn't really recognize Word anymore, and displays weird symbols instead of font characters.
Logfile of HijackThis v1.99.1
Scan saved at 22:05:50, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
@+
Hi Bertha!
It's good work ;-)
Yes, you can hide your folders again...
The Avast scan you mean???
It crashes, what do you mean???
Please post a new HijackThis in normal mode
++
--
**We can also build something beautiful with the stones that impede the way (J.W. VON GOETHE)**
It's good work ;-)
Yes, you can hide your folders again...
The Avast scan you mean???
It crashes, what do you mean???
Please post a new HijackThis in normal mode
++
--
**We can also build something beautiful with the stones that impede the way (J.W. VON GOETHE)**
Well, thanks to you for the good work...
No no... when I talk about the scan... I mean the scanner of the printer.
With the HijackThis tutorial do you think I can manage to understand what's wrong with it?
For example, I believe there are some unnecessary HP stuff there, right?
Logfile of HijackThis v1.99.1
Scan saved at 23:04:30, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
No no... when I talk about the scan... I mean the scanner of the printer.
With the HijackThis tutorial do you think I can manage to understand what's wrong with it?
For example, I believe there are some unnecessary HP stuff there, right?
Logfile of HijackThis v1.99.1
Scan saved at 23:04:30, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
re
lol ok !
did you install the firewall??? be careful, it's important!!
we didn't touch a scanner anyway...
what's wrong???
regarding the HP lines, it's better to leave them, they're the updates, quick launch...
++
--
**We can also build something beautiful with the stones that obstruct the way (J.W. VON GOETHE)**
lol ok !
did you install the firewall??? be careful, it's important!!
we didn't touch a scanner anyway...
what's wrong???
regarding the HP lines, it's better to leave them, they're the updates, quick launch...
++
--
**We can also build something beautiful with the stones that obstruct the way (J.W. VON GOETHE)**
Hi,
No, I haven't done it yet... but I will do it. Isn't the Windows firewall sufficient?
No, what happens with the scanner is that when I scan a document and send it to Word, for example, it gives me a lot of strange symbols, but not in Acrobat. I reinstalled it (the printer CD), but the problem remains the same; it might be related to Word?
No, I haven't done it yet... but I will do it. Isn't the Windows firewall sufficient?
No, what happens with the scanner is that when I scan a document and send it to Word, for example, it gives me a lot of strange symbols, but not in Acrobat. I reinstalled it (the printer CD), but the problem remains the same; it might be related to Word?
Hi
the Windows firewall isn't very useful :)
security the Windows XP firewall
I don't know if it's from Word ...
check this:
go to control panel<system<hardware<device manager and see if there are any yellow "?" or "!" points
if that's the case: right-click and update drivers
and update your Windows!
@+
--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETH)**
the Windows firewall isn't very useful :)
security the Windows XP firewall
I don't know if it's from Word ...
check this:
go to control panel<system<hardware<device manager and see if there are any yellow "?" or "!" points
if that's the case: right-click and update drivers
and update your Windows!
@+
--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETH)**
Hello Green Day,
I've installed Kerio, thanks a lot.
For the scanner malfunction with Word, it doesn't come from the hardware configuration, no yellow exclamation point. I don't know, but it's okay... I'll see later. I was also thinking about that line we removed: HKCU\software\Microsoft\Windows\CurrentVersion\policies\System,DisableRegedit=1
Since it's a problem with fonts not recognized by the scanner... I was wondering, what does that line we removed correspond to?
Thank you very much for your help!
But did you study this? Is it your profession or a passion?
Uh, it might be an awkward question but it's curiosity...
Have a good day and see you next time
Bertha
I've installed Kerio, thanks a lot.
For the scanner malfunction with Word, it doesn't come from the hardware configuration, no yellow exclamation point. I don't know, but it's okay... I'll see later. I was also thinking about that line we removed: HKCU\software\Microsoft\Windows\CurrentVersion\policies\System,DisableRegedit=1
Since it's a problem with fonts not recognized by the scanner... I was wondering, what does that line we removed correspond to?
Thank you very much for your help!
But did you study this? Is it your profession or a passion?
Uh, it might be an awkward question but it's curiosity...
Have a good day and see you next time
Bertha
Re-hello :-)
for 07: access to the Registry was blocked: execution of Regedit was restricted by modifying a key in the Registry, by fixing it and deleting the value in the registry, this restriction can be canceled, I don't think it has anything to do with Word...
But did you study that there? Is it your job or a passion?
Uh, it might be an awkward question but it's curiosity..
It's not my profession, nor my field of study, just a simple passion ;-)))
it's not an awkward question either lol
a little reading in the meantime:
security protect a computer against internet malware
looking forward to it, happy surfing!
@+
--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETHE)**
for 07: access to the Registry was blocked: execution of Regedit was restricted by modifying a key in the Registry, by fixing it and deleting the value in the registry, this restriction can be canceled, I don't think it has anything to do with Word...
But did you study that there? Is it your job or a passion?
Uh, it might be an awkward question but it's curiosity..
It's not my profession, nor my field of study, just a simple passion ;-)))
it's not an awkward question either lol
a little reading in the meantime:
security protect a computer against internet malware
looking forward to it, happy surfing!
@+
--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETHE)**
Hi Green Day,
I think I still need your help, just a little bit, and this time it's not too serious. Here's the thing: it's about the display. I can no longer get the Windows XP theme. When I go to "display," "display properties," "appearances," "windows and buttons," I only have the option to choose the Classic Windows theme, not Windows XP. This means that I have a Windows XP laptop but with a Classic Windows display, and this happened since my virus infection... Do you have any idea where this might be coming from?
Otherwise, for a simple passion... you must have had to deal with it often... or maybe you have an impeccable logic.
Have a good Sunday @ +
I think I still need your help, just a little bit, and this time it's not too serious. Here's the thing: it's about the display. I can no longer get the Windows XP theme. When I go to "display," "display properties," "appearances," "windows and buttons," I only have the option to choose the Classic Windows theme, not Windows XP. This means that I have a Windows XP laptop but with a Classic Windows display, and this happened since my virus infection... Do you have any idea where this might be coming from?
Otherwise, for a simple passion... you must have had to deal with it often... or maybe you have an impeccable logic.
Have a good Sunday @ +
Hi
with a bit of experience, a logic starts to appear ;-))
# Download this: (thanks to S!RI for this little program).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Run it, double click on Smitfraudfix.cmd, choose option 1,
here's what it looks like: http://siri.urz.free.fr/Fix/SmitfraudFix.php
it will generate a report: please copy/paste it on the post.
++
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
with a bit of experience, a logic starts to appear ;-))
# Download this: (thanks to S!RI for this little program).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Run it, double click on Smitfraudfix.cmd, choose option 1,
here's what it looks like: http://siri.urz.free.fr/Fix/SmitfraudFix.php
it will generate a report: please copy/paste it on the post.
++
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
Hello Green Day....still here ...
here is the report:
SmitFraudFix v2.122
Report made at 18:05:25.60, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BERTHO~1\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My homepage"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the following keys are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the following keys are not necessarily infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Search infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» End
here is the report:
SmitFraudFix v2.122
Report made at 18:05:25.60, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BERTHO~1\Favorites
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop items
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My homepage"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the following keys are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the following keys are not necessarily infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Search infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» End
re
still presente yes :-)
Restart the PC in safe mode: tap the F8 key on your keyboard (or F5) and choose safe mode)
- Open the "SmitfraudFix" folder and double-click on "Smitfraudfix.cmd", select option 2 and answer yes to everything.
Save the report and then copy/paste the report on the forum please.
@+
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE
)**
still presente yes :-)
Restart the PC in safe mode: tap the F8 key on your keyboard (or F5) and choose safe mode)
- Open the "SmitfraudFix" folder and double-click on "Smitfraudfix.cmd", select option 2 and answer yes to everything.
Save the report and then copy/paste the report on the forum please.
@+
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE
)**
re,
As it turns out, the idea we have of the computer enthusiast is pretty silly: a young guy with glasses and pimples.......
Here is the report:
SmitFraudFix v2.122
Report made at 19:03:02,20, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Stopping processes
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temporary Files
»»»»»»»»»»»»»»»»»»»»»»»» Cleaning the registry
Cleanup completed.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
As it turns out, the idea we have of the computer enthusiast is pretty silly: a young guy with glasses and pimples.......
Here is the report:
SmitFraudFix v2.122
Report made at 19:03:02,20, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Stopping processes
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temporary Files
»»»»»»»»»»»»»»»»»»»»»»»» Cleaning the registry
Cleanup completed.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
re
ok,
download this and unzip it
http://pageperso.aol.fr/Balltrap34/luna.zip
then place it in C:\WINDOWS\Resources\Themes\Luna
and double click on it
Then try again to revert to the XP style
++
--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE
)**
ok,
download this and unzip it
http://pageperso.aol.fr/Balltrap34/luna.zip
then place it in C:\WINDOWS\Resources\Themes\Luna
and double click on it
Then try again to revert to the XP style
++
--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE
)**
FANTASTIC !!!
It works, ADMIRATION!
You know you could come open a shop here in Dakar, it would go over like a ton of bricks. Everyone has a virus on their device right now!! Do you think the ISP is responsible for anything in this wave of viruses here?
THANK YOU VERY MUCH.
Bertha @ +
In Africa maybe!
It works, ADMIRATION!
You know you could come open a shop here in Dakar, it would go over like a ton of bricks. Everyone has a virus on their device right now!! Do you think the ISP is responsible for anything in this wave of viruses here?
THANK YOU VERY MUCH.
Bertha @ +
In Africa maybe!
I am really happy for you ;-)))
Dakar: it must be nice ^^
ISPs are not responsible for this avalanche of malware, are they? It’s people like you and me who have fun creating these programs or bits of programs solely to ruin our lives and violate our privacy...
However, I think ISPs could make an effort regarding prevention and the risks of malware...
An idea of what already exists:
different types of malware
a bit more reading:
https://sebsauvage.net/safehex.html
security protecting a computer against internet malware
happy surfing!
@+
--
**We can also build something beautiful with the stones that block the way (J.W. VON GOETHE)**
Dakar: it must be nice ^^
ISPs are not responsible for this avalanche of malware, are they? It’s people like you and me who have fun creating these programs or bits of programs solely to ruin our lives and violate our privacy...
However, I think ISPs could make an effort regarding prevention and the risks of malware...
An idea of what already exists:
different types of malware
a bit more reading:
https://sebsauvage.net/safehex.html
security protecting a computer against internet malware
happy surfing!
@+
--
**We can also build something beautiful with the stones that block the way (J.W. VON GOETHE)**
- 1
- 2
Suivant