Infected by I-worm/brontok.C

Solved
bertha -  
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   -
O1 - Hosts: O1 - Hosts: O1 - Hosts:
O1 - Hosts:
Yahoo! GeoCities
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
Sorry, this GeoCities site is currently unavailable.
O1 - Hosts:

The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later.

O1 - Hosts:

Are you the site owner? O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit! O1 - Hosts: Find out how.

O1 - Hosts:

Learn more about data transfer.

O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Yahoo! GeoCities O1 - Hosts:
SPONSORED LINKS
O1 - Hosts: O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Reliable plans include domain & 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Includes starter web page, email & domain forwarding, 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: O1 - Hosts:
$50 setup fee waived. A reliable ecommerce plan, 24x7 support.
O1 - Hosts: O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Get your own web site at
Yahoo! GeoCities O1 - Hosts: Hosted by Yahoo! Web Hosting O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Copyright © O1 - Hosts: 2005 Yahoo! Inc. All rights reserved
O1 - Hosts: Privacy Policy O1 - Hosts: - Copyright Policy O1 - Hosts: - Guidelines O1 - Hosts: - Terms of Service O1 - Hosts: - Help O1 - Hosts:
O1 - Hosts: O1 - Hosts:

23 réponses

  • 1
  • 2
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Oops! I just saw it :)

Please stay on the same thread!

Otherwise, we're going to get lost ;)

Open the file "C:\WINDOWS\system32\drivers\etc\hosts" with Notepad, delete all its content and paste the following text (in bold) in its place:

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP
# for Windows.
#
# This file contains the mappings of IP addresses to host names.
# Each entry should be on a separate line. The IP address should be placed
# in the first column, followed by the corresponding host name. The
# IP address and the host name must be separated by at least one space.
#
# Additionally, comments (like this one) may be inserted on
# separate lines or after the computer name. They are indicated by the
# '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # client host x

127.0.0.1 localhost


Go to "File" > "Save", close everything and restart your PC
Then, do a "hijackthis" and post the new report with the results for your initial issue

Next, try to download AVG and run the scan in safe mode

Keep us updated, good luck, @+

**In truth, the path matters little, the will to arrive is all that matters (A. Camus)**
1
did71 Posted messages 2187 Status Contributeur sécurité 36
 
re green,

the host will restore all of that!

see you!
1
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
seen ;-)

@+
--
**In truth, the journey matters little, the will to arrive is enough for everything ( A.Camus ) **
0
bertha
 
Good evening, I've done what you both said, here’s the result
Is it better?
I still have my kesenjangan file at startup.
Well, I will scan with AVG to see. In any case, thanks again and greetings from Senegal where it’s terribly hot!
Bertha

Logfile of HijackThis v1.99.1
Scan saved at 00:31:06, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Quick startup of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quick launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
0
did71 Posted messages 2187 Status Contributeur sécurité 36
 
re,

yes, that’s better!

there are still infections!

green is going to get rid of them!

see you!
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hello you

Aww Did! You could have continued anyway ;-P

Bretha:

C:\windows\kesenjangansosial.exe. It asks me for it every time I start up. What is this file for?

To answer your question, yes it’s a nasty one! And you need to delete that bolded file!

Please do steps 1/ and 2/ from this link:

virus preliminary disinfection method version en

Catch you later
--
**In truth, the path matters little, the will to arrive is all that matters (A.Camus)**
0
bertha
 
Re
Hello Green D,
Here is the AVG analysis, I will do the scan with Bit Defender now
Thank you

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 15:59:36 16/11/2006

+ Scan results:



C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\BERTHOU Claire\Cookies\berthou claire@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\DIAGNE Mody\Cookies\diagne mody@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006805.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006806.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006807.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006808.exe -> Worm.Brontok.q : Cleaned and saved (quarantined).
C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP48\A0006809.scr -> Worm.Brontok.q : Cleaned and saved (quarantined).


End of report
0
bertha
 
Hello Green Day,
here's the final report from BitDefender!!! OOPS I still had all this in there or did it scan what I had set in 40?

BitDefender Online Scanner



Scan report generated at: Thu, Nov 16, 2006 - 17:48:52





Scan path: C:\;D:\;E:\;







Statistics

Time
00:54:40

Files
515563

Folders
5176

Boot Sectors
4

Archives
8662

Packed Files
63672




Results

Identified Viruses
1

Infected Files
155

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
310




Engines Info

Virus Definitions
316345

Engine build
AVCORE v1.0 (build 2355) (i386) (Sep 25 2006 13:46:24)

Scan plugins
13

Archive plugins
38

Unpack plugins
6

E-mail plugins
6

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\actualités.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\administratif.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\art et objet.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\assoc humanitaire.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\billets d'avion.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\boulot claire.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Brengkolang.com.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CEEXE~1.BAC=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cola.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\csrss.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine bretonne.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\cuisine.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\CV et Emploi.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\divers claire.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\DOCUME~1.BAC=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\E P S.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education enfant.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\education mody.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Emploi du temps ce2.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Empty.pif.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\EVENEMENTS A FETER.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Films.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\formation claire.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Géométrie.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\INETIN~1.BAC=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\informatique a lecole.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\logiciels pedagogiques.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\lsass.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Musique, paroles.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Problémes de Ce2.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Programmations.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Projets pedagogiques.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Romans CE2.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Résolution de problemes.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\services.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Sites pour instits.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\smss.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\SYNDICAT ENSEIGNANT.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\THEATRE.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Théatre.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WPOURA~1.BAC=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\Wbcam.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\BERTHOU Claire\.housecall6.6\Quarantine\WINAMP.exe.bac_a00460=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\actualités.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\administratif.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\anglais - new live 6°.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ANNUAIRE.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\art et objet.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\ARTS PLASTIQUES.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\billets d'avion.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BIO.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Blog Mody.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\BLOG.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\boulot claire.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Brengkolang.com.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Bretagne.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CAMION.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\Carnaval.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\cartes de voeux.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Infected with: Generic.Brontok.496D42C5

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\CE2.exe.bac_a02680=>(Quarantine-4)
Deleted

C:\Documents and Settings\DIAGNE Mody\.housecall6.6\Quarantine\chants
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hi

all of this is the quarantine

please post a new hijackthis

++
--
**We can also build something beautiful with the stones that obstruct the path ( J.W.VON GOETH
)**
0
bertha
 
Good evening Green Day, I (I completely understand your position)

here is the latest Hijack This report, soooo is it good? please tell me it's good !!!!

Bertha


Logfile of HijackThis v1.99.1
Scan saved at 22:58:51, on 16/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"
O4 - Global Startup: HP Photosmart Premier Quick Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Reader Quick Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
0
did71 Posted messages 2187 Status Contributeur sécurité 36
 
Good evening you,

sorry Green but I helped with the host file, then I prefer to let the first helper take care of it so as not to confuse things!

see you later
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Good evening Bertha!

We're almost there :-)

1) Show system folders and hidden files:
Open My Computer
- Tools --> Folder Options
- View --> Advanced settings
- Check: Show hidden files and folders
- Check: Show system files
- Uncheck: Hide extensions for known file types
- Uncheck: Hide protected operating system files (recommended)
Respond Yes to the message
Click on "Apply to all folders"
Click OK

2) Disable System Restore

* Click the Start button.
* Right-click on My Computer and then click on Properties.
* In the System Restore tab, select the option to Disable System Restore or Disable System Restore on all drives

(you can reactivate it at the end of the process)

3) Relaunch HijackThis: choose "do a scan only", check the box in front of the lines below and click "fix checked" at the bottom:

F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\KesenjanganSosial.exe"

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\ShellNew\RakyatKelaparan.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus-5226] "C:\Documents and Settings\BERTHOU Claire\Local Settings\Application Data\smss.exe"

O4 - Global Startup: Quick Launch of Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in a background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a foreground tab - res://C:\Program Files\Windows Live

O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123w.bay123.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab

4) Search and delete the following bold files: (if present)

C:\WINDOWS\KesenjanganSosial.exe
C:\WINDOWS\ShellNew\RakyatKelaparan.exe

5) do this:

start==> run==> type: regedit
then by clicking on the +
follow this path
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_current_user... etc..
and delete DisableRegedit=1 by right-clicking on it and delete

6) download and run this:

* CleanUp40 (which eliminates temporary files + cookies: free)
http://pageperso.aol.fr/Balltrap34/CleanUp40.exe

tutorial: (thanks to Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm

* Ccleaner: Download and install this, in the left column click on "errors", check all the boxes, then click on "search for errors" at the bottom, once finished, click on "repair errors" and you will get a message to back up your registry, you say "yes" and then repeat until it finds no more errors.

* Relaunch Ccleaner, go to the "cleaner" tab on the left, uncheck the last box (Advanced if it
is checked) and then click on "run the cleaning"

ccleaner

tutorial: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

==> click on start < < run and type: Prefetch
and delete all the contents of this folder!

7) install a firewall:

kerio

tutorial: to configure and understand Kerio
https://www.vulgarisation-informatique.com/kerio.php

8) post a new hijackthis and specify your issues if any remain

don't hesitate to ask questions!

good luck, @+

**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
0
bertha
 
Hi Green Day,
I was about to finally wrap things up with the instructions you gave me... but I don't understand why I can't find "folder options" in tools, in my computer, or even in the control panel under "appearance and themes." I don't have it. I don't have any problem on the other PC. It might be related to the fact that it's a Home XP and not Pro, as I said at the beginning. I got it wrong; it's the PC that's Pro, while the laptop is Home.
Or maybe I'm just really clueless... that could be it too.
0
bertha
 
Hello Green Day, I did all the points except 1, 4, and 5 because I couldn't, a window opens with a message from the system administrator that blocks this action, and 7 because I haven't had the time yet.

Thank you GD

Logfile of HijackThis v1.99.1
Scan saved at 13:04:34, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\CleanUp!\cleanup.exe
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menu item: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menu item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hi

you should have it! For XP Pro and Home, it's the same; the difference is not at that level...

window that opens with a message from the system administrator blocking this action,

do you have an administrator or limited rights session???

++

--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE)**
0
bertha
 
Hi Green Day,
Ok Ok, I had to boot in safe mode and then log in as an administrator, but I didn't know that!!!!

So I did everything again.... I even "fixed checked" with HijackThis the lines I had deleted before.
Should I re-check and uncheck the lines in Folder Options now that I have finished the process?
Thank you so much for your patience and dedication... I have learned a lot but my eyes are glazed over. Here is the latest HijackThis. Otherwise, my scanner has been acting up since all these adjustments; it doesn't really recognize Word anymore, and displays weird symbols instead of font characters.

Logfile of HijackThis v1.99.1
Scan saved at 22:05:50, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\BERTHOU Claire\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

@+
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hi Bertha!

It's good work ;-)

Yes, you can hide your folders again...

The Avast scan you mean???

It crashes, what do you mean???

Please post a new HijackThis in normal mode

++
--
**We can also build something beautiful with the stones that impede the way (J.W. VON GOETHE)**
0
bertha
 
Well, thanks to you for the good work...
No no... when I talk about the scan... I mean the scanner of the printer.
With the HijackThis tutorial do you think I can manage to understand what's wrong with it?
For example, I believe there are some unnecessary HP stuff there, right?

Logfile of HijackThis v1.99.1
Scan saved at 23:04:30, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\BERTHOU Claire\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - Global Startup: Quick Start of HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Open in a new background tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?12cff11c25674581b0100b75f2b36f09
O8 - Extra context menu item: Open in a new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?12cff11c25674581b0100b75f2b36f09
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Search - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC41BF28-EA0B-4E11-80C5-6062DF9688A7}: NameServer = 213.154.95.126 213.154.64.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
re

lol ok !

did you install the firewall??? be careful, it's important!!

we didn't touch a scanner anyway...

what's wrong???

regarding the HP lines, it's better to leave them, they're the updates, quick launch...

++

--
**We can also build something beautiful with the stones that obstruct the way (J.W. VON GOETHE)**
0
bertha
 
Hi,

No, I haven't done it yet... but I will do it. Isn't the Windows firewall sufficient?

No, what happens with the scanner is that when I scan a document and send it to Word, for example, it gives me a lot of strange symbols, but not in Acrobat. I reinstalled it (the printer CD), but the problem remains the same; it might be related to Word?
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hi

the Windows firewall isn't very useful :)

security the Windows XP firewall

I don't know if it's from Word ...

check this:

go to control panel<system<hardware<device manager and see if there are any yellow "?" or "!" points

if that's the case: right-click and update drivers

and update your Windows!

@+
--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETH)**
0
bertha
 
Hello Green Day,

I've installed Kerio, thanks a lot.
For the scanner malfunction with Word, it doesn't come from the hardware configuration, no yellow exclamation point. I don't know, but it's okay... I'll see later. I was also thinking about that line we removed: HKCU\software\Microsoft\Windows\CurrentVersion\policies\System,DisableRegedit=1
Since it's a problem with fonts not recognized by the scanner... I was wondering, what does that line we removed correspond to?

Thank you very much for your help!
But did you study this? Is it your profession or a passion?
Uh, it might be an awkward question but it's curiosity...
Have a good day and see you next time
Bertha
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Re-hello :-)

for 07: access to the Registry was blocked: execution of Regedit was restricted by modifying a key in the Registry, by fixing it and deleting the value in the registry, this restriction can be canceled, I don't think it has anything to do with Word...

But did you study that there? Is it your job or a passion?
Uh, it might be an awkward question but it's curiosity..


It's not my profession, nor my field of study, just a simple passion ;-)))

it's not an awkward question either lol

a little reading in the meantime:

security protect a computer against internet malware

looking forward to it, happy surfing!

@+

--
**We can also build something beautiful with the stones that obstruct the path (J.W.VON GOETHE)**
0
bertha
 
Hi Green Day,

I think I still need your help, just a little bit, and this time it's not too serious. Here's the thing: it's about the display. I can no longer get the Windows XP theme. When I go to "display," "display properties," "appearances," "windows and buttons," I only have the option to choose the Classic Windows theme, not Windows XP. This means that I have a Windows XP laptop but with a Classic Windows display, and this happened since my virus infection... Do you have any idea where this might be coming from?

Otherwise, for a simple passion... you must have had to deal with it often... or maybe you have an impeccable logic.

Have a good Sunday @ +
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
Hi

with a bit of experience, a logic starts to appear ;-))

# Download this: (thanks to S!RI for this little program).

http://siri.urz.free.fr/Fix/SmitfraudFix.zip

Run it, double click on Smitfraudfix.cmd, choose option 1,
here's what it looks like: http://siri.urz.free.fr/Fix/SmitfraudFix.php
it will generate a report: please copy/paste it on the post.

++
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE)**
0
Bertha
 
Hello Green Day....still here ...
here is the report:


SmitFraudFix v2.122

Report made at 18:05:25.60, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\BERTHOU Claire\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BERTHO~1\Favorites


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop items

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My homepage"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Warning, the following keys are not necessarily infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Warning, the following keys are not necessarily infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Search infection wininet.dll


»»»»»»»»»»»»»»»»»»»»»»»» End
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
re

still presente yes :-)

Restart the PC in safe mode: tap the F8 key on your keyboard (or F5) and choose safe mode)

- Open the "SmitfraudFix" folder and double-click on "Smitfraudfix.cmd", select option 2 and answer yes to everything.

Save the report and then copy/paste the report on the forum please.

@+
--
**We can also build something beautiful with the stones that obstruct the way (J.W.VON GOETHE
)**
0
bertha
 
re,
As it turns out, the idea we have of the computer enthusiast is pretty silly: a young guy with glasses and pimples.......

Here is the report:


SmitFraudFix v2.122

Report made at 19:03:02,20, 19/11/2006
Executed from C:\Documents and Settings\BERTHOU Claire\Desktop\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executed in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Stopping processes


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temporary Files


»»»»»»»»»»»»»»»»»»»»»»»» Cleaning the registry

Cleanup completed.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Warning, the keys that follow are not necessarily infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
re

LOL!!! IT is not a field reserved for men! No way, lol
( or maybe it is less and less... )

look now if you have found the style of XP

++

--
**We can also build something beautiful with the stones that block the way ( J.W.VON GOETH
)**
0
bertha
 
Well no, unfortunately...
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
re

ok,

download this and unzip it
http://pageperso.aol.fr/Balltrap34/luna.zip

then place it in C:\WINDOWS\Resources\Themes\Luna
and double click on it

Then try again to revert to the XP style

++
--
**We can also build something beautiful with the stones that obstruct the path (J.W. VON GOETHE
)**
0
bertha
 
FANTASTIC !!!

It works, ADMIRATION!

You know you could come open a shop here in Dakar, it would go over like a ton of bricks. Everyone has a virus on their device right now!! Do you think the ISP is responsible for anything in this wave of viruses here?

THANK YOU VERY MUCH.

Bertha @ +
In Africa maybe!
0
green day Posted messages 26374 Registration date   Status Modérateur, Contributeur sécurité Last intervention   2 166
 
I am really happy for you ;-)))

Dakar: it must be nice ^^

ISPs are not responsible for this avalanche of malware, are they? It’s people like you and me who have fun creating these programs or bits of programs solely to ruin our lives and violate our privacy...

However, I think ISPs could make an effort regarding prevention and the risks of malware...

An idea of what already exists:

different types of malware

a bit more reading:

https://sebsauvage.net/safehex.html

security protecting a computer against internet malware

happy surfing!

@+

--
**We can also build something beautiful with the stones that block the way (J.W. VON GOETHE)**
0
  • 1
  • 2