A voir également:
- Trojan virtumond
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Anti trojan - Télécharger - Antivirus & Antimalwares
- Virus trojan al11 ✓ - Forum Virus
- Csrss.exe trojan fr ✓ - Forum Virus
- Trojan win32 - Forum Virus
9 réponses
Bonsoir,
dans un premier temps
Télécharge Hijackthis
Voir Tuto et Téléchargement :
http://forum.telecharger.01net.com/microhebdo/questions_techniques_diverses/securite/tuto2_hijackthis_202_version_install-346620/messages-1.html
poste moi le rapport
merci
@+
dans un premier temps
Télécharge Hijackthis
Voir Tuto et Téléchargement :
http://forum.telecharger.01net.com/microhebdo/questions_techniques_diverses/securite/tuto2_hijackthis_202_version_install-346620/messages-1.html
poste moi le rapport
merci
@+
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:01:31, on 02/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\ysnzpmfv.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [54a58e5f] rundll32.exe "C:\WINDOWS\system32\kjonfohu.dll",b
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [PowerDVD] "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" /autostart
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bw+0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O18 - Protocol: offline-8876480 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O24 - Desktop Component 0: (no name) - http://www.restaurant-saintcyrlecques.com/contact.php?
Scan saved at 00:01:31, on 02/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\ysnzpmfv.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [54a58e5f] rundll32.exe "C:\WINDOWS\system32\kjonfohu.dll",b
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [PowerDVD] "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" /autostart
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bw+0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O18 - Protocol: offline-8876480 - {55072E3E-542B-4688-98CA-35FB053302E1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O24 - Desktop Component 0: (no name) - http://www.restaurant-saintcyrlecques.com/contact.php?
Télécharge Vundofix (de Atribune) sur ton Bureau
http://www.atribune.org/ccount/click.php?id=4
- Double-clique VundoFix.exe afin de le lancer.
- Clique sur le bouton Scan for Vundo.
- Lorsque le scan est complété, clique sur le bouton Remove Vundo.
- Une invite te demandera si tu veux supprimer les fichiers, clique YES
- Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
- Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
- Démarre ton PC à nouveau.
- Copie/colle le contenu du rapport situé dans C:\vundofix.txt
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
@+
http://www.atribune.org/ccount/click.php?id=4
- Double-clique VundoFix.exe afin de le lancer.
- Clique sur le bouton Scan for Vundo.
- Lorsque le scan est complété, clique sur le bouton Remove Vundo.
- Une invite te demandera si tu veux supprimer les fichiers, clique YES
- Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
- Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
- Démarre ton PC à nouveau.
- Copie/colle le contenu du rapport situé dans C:\vundofix.txt
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
@+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonjour,
JE SAIS PAS SI Céi ca le rapport voila ce que j ai trouve merci
[11/01/2007, 23:43:27] - VirtumundoBeGone v1.5 ( "C:\DOCUME~1\BRICEB~1\MESDOC~1\BRICEB~1\virtumundobegone.exe" )
[11/01/2007, 23:43:32] - Detected System Information:
[11/01/2007, 23:43:32] - Windows Version: 5.1.2600, Service Pack 2
[11/01/2007, 23:43:33] - Current Username: BRICE BONADEI (Admin)
[11/01/2007, 23:43:33] - Windows is in NORMAL mode.
[11/01/2007, 23:43:34] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:34] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:34] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - No filename found. Continuing.
[11/01/2007, 23:43:34] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:34] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:35] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:35] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:35] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:35] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:35] - Found: HKLM\...\Winlogon\Notify\ysnzpmfv - This is probably Virtumundo.
[11/01/2007, 23:43:35] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/01/2007, 23:43:35] - BHO list has been changed! Starting over...
[11/01/2007, 23:43:35] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:36] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - No filename found. Continuing.
[11/01/2007, 23:43:36] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:36] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:37] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:37] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:37] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:37] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/01/2007, 23:43:37] - ALERT: Found MSEvents Object!
[11/01/2007, 23:43:37] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:37] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:37] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:37] - *** Detected MSEvents Object
[11/01/2007, 23:43:37] - Trying to remove MSEvents Object...
[11/01/2007, 23:43:38] - Terminating Process: IEXPLORE.EXE
[11/01/2007, 23:43:40] - Terminating Process: RUNDLL32.EXE
[11/01/2007, 23:43:42] - Disabling Automatic Shell Restart
[11/01/2007, 23:43:42] - Terminating Process: EXPLORER.EXE
[11/01/2007, 23:43:44] - Suspending the NT Session Manager System Service
[11/01/2007, 23:43:45] - Terminating Windows NT Logon/Logoff Manager
[11/01/2007, 23:43:49] - Re-enabling Automatic Shell Restart
[11/01/2007, 23:43:50] - File to disable: C:\WINDOWS\system32\ysnzpmfv.dll
[11/01/2007, 23:43:50] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:55] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:57] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:58] - Deleting ATLEvents/MSEvents Registry entries
[11/01/2007, 23:43:58] - Removing HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:58] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:58] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:58] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:58] - No filename found. Continuing.
[11/01/2007, 23:43:59] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:27] - VirtumundoBeGone v1.5 ( "C:\DOCUME~1\BRICEB~1\MESDOC~1\BRICEB~1\virtumundobegone.exe" )
[11/01/2007, 23:43:32] - Detected System Information:
[11/01/2007, 23:43:32] - Windows Version: 5.1.2600, Service Pack 2
[11/01/2007, 23:43:33] - Current Username: BRICE BONADEI (Admin)
[11/01/2007, 23:43:33] - Windows is in NORMAL mode.
[11/01/2007, 23:43:34] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:34] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:34] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - No filename found. Continuing.
[11/01/2007, 23:43:34] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:34] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:35] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:35] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:35] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:35] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:35] - Found: HKLM\...\Winlogon\Notify\ysnzpmfv - This is probably Virtumundo.
[11/01/2007, 23:43:35] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/01/2007, 23:43:35] - BHO list has been changed! Starting over...
[11/01/2007, 23:43:35] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:36] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - No filename found. Continuing.
[11/01/2007, 23:43:36] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:36] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:37] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:37] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:37] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:37] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/01/2007, 23:43:37] - ALERT: Found MSEvents Object!
[11/01/2007, 23:43:37] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:37] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:37] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:37] - *** Detected MSEvents Object
[11/01/2007, 23:43:37] - Trying to remove MSEvents Object...
[11/01/2007, 23:43:38] - Terminating Process: IEXPLORE.EXE
[11/01/2007, 23:43:40] - Terminating Process: RUNDLL32.EXE
[11/01/2007, 23:43:42] - Disabling Automatic Shell Restart
[11/01/2007, 23:43:42] - Terminating Process: EXPLORER.EXE
[11/01/2007, 23:43:44] - Suspending the NT Session Manager System Service
[11/01/2007, 23:43:45] - Terminating Windows NT Logon/Logoff Manager
[11/01/2007, 23:43:49] - Re-enabling Automatic Shell Restart
[11/01/2007, 23:43:50] - File to disable: C:\WINDOWS\system32\ysnzpmfv.dll
[11/01/2007, 23:43:50] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:55] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:57] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:58] - Deleting ATLEvents/MSEvents Registry entries
[11/01/2007, 23:43:58] - Removing HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:58] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:58] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:58] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:58] - No filename found. Continuing.
[11/01/2007, 23:43:59] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:59] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:59] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:59] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:59] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:59] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:59] - Finishing up...
[11/01/2007, 23:44:00] - A restart is needed.
[11/01/2007, 23:44:04] - Attempting to Restart via STOP error (Blue Screen!)
[11/02/2007, 16:47:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\BRICE BONADEI\Mes documents\Brice BONADEI\virtumundobegone.exe" )
[11/02/2007, 16:47:21] - User choose NOT to continue. Exiting...
[11/01/2007, 23:43:59] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:59] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:59] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:59] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:59] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:59] - Finishing up...
[11/01/2007, 23:44:00] - A restart is needed.
[11/01/2007, 23:44:04] - Attempting to Restart via STOP error (Blue Screen!)
[11/02/2007, 16:47:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\BRICE BONADEI\Mes documents\Brice BONADEI\virtumundobegone.exe" )
[11/02/2007, 16:47:21] - User choose NOT to continue. Exiting...
JE SAIS PAS SI Céi ca le rapport voila ce que j ai trouve merci
[11/01/2007, 23:43:27] - VirtumundoBeGone v1.5 ( "C:\DOCUME~1\BRICEB~1\MESDOC~1\BRICEB~1\virtumundobegone.exe" )
[11/01/2007, 23:43:32] - Detected System Information:
[11/01/2007, 23:43:32] - Windows Version: 5.1.2600, Service Pack 2
[11/01/2007, 23:43:33] - Current Username: BRICE BONADEI (Admin)
[11/01/2007, 23:43:33] - Windows is in NORMAL mode.
[11/01/2007, 23:43:34] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:34] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:34] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - No filename found. Continuing.
[11/01/2007, 23:43:34] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:34] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:35] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:35] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:35] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:35] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:35] - Found: HKLM\...\Winlogon\Notify\ysnzpmfv - This is probably Virtumundo.
[11/01/2007, 23:43:35] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/01/2007, 23:43:35] - BHO list has been changed! Starting over...
[11/01/2007, 23:43:35] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:36] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - No filename found. Continuing.
[11/01/2007, 23:43:36] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:36] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:37] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:37] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:37] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:37] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/01/2007, 23:43:37] - ALERT: Found MSEvents Object!
[11/01/2007, 23:43:37] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:37] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:37] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:37] - *** Detected MSEvents Object
[11/01/2007, 23:43:37] - Trying to remove MSEvents Object...
[11/01/2007, 23:43:38] - Terminating Process: IEXPLORE.EXE
[11/01/2007, 23:43:40] - Terminating Process: RUNDLL32.EXE
[11/01/2007, 23:43:42] - Disabling Automatic Shell Restart
[11/01/2007, 23:43:42] - Terminating Process: EXPLORER.EXE
[11/01/2007, 23:43:44] - Suspending the NT Session Manager System Service
[11/01/2007, 23:43:45] - Terminating Windows NT Logon/Logoff Manager
[11/01/2007, 23:43:49] - Re-enabling Automatic Shell Restart
[11/01/2007, 23:43:50] - File to disable: C:\WINDOWS\system32\ysnzpmfv.dll
[11/01/2007, 23:43:50] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:55] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:57] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:58] - Deleting ATLEvents/MSEvents Registry entries
[11/01/2007, 23:43:58] - Removing HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:58] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:58] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:58] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:58] - No filename found. Continuing.
[11/01/2007, 23:43:59] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:27] - VirtumundoBeGone v1.5 ( "C:\DOCUME~1\BRICEB~1\MESDOC~1\BRICEB~1\virtumundobegone.exe" )
[11/01/2007, 23:43:32] - Detected System Information:
[11/01/2007, 23:43:32] - Windows Version: 5.1.2600, Service Pack 2
[11/01/2007, 23:43:33] - Current Username: BRICE BONADEI (Admin)
[11/01/2007, 23:43:33] - Windows is in NORMAL mode.
[11/01/2007, 23:43:34] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:34] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:34] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - No filename found. Continuing.
[11/01/2007, 23:43:34] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:34] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:34] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:35] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:35] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:35] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:35] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[11/01/2007, 23:43:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:35] - Checking for HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:35] - Found: HKLM\...\Winlogon\Notify\ysnzpmfv - This is probably Virtumundo.
[11/01/2007, 23:43:35] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[11/01/2007, 23:43:35] - BHO list has been changed! Starting over...
[11/01/2007, 23:43:35] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:36] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - No filename found. Continuing.
[11/01/2007, 23:43:36] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:36] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:36] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:37] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:37] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:37] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:37] - BHO 6: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[11/01/2007, 23:43:37] - ALERT: Found MSEvents Object!
[11/01/2007, 23:43:37] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:37] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:37] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:37] - *** Detected MSEvents Object
[11/01/2007, 23:43:37] - Trying to remove MSEvents Object...
[11/01/2007, 23:43:38] - Terminating Process: IEXPLORE.EXE
[11/01/2007, 23:43:40] - Terminating Process: RUNDLL32.EXE
[11/01/2007, 23:43:42] - Disabling Automatic Shell Restart
[11/01/2007, 23:43:42] - Terminating Process: EXPLORER.EXE
[11/01/2007, 23:43:44] - Suspending the NT Session Manager System Service
[11/01/2007, 23:43:45] - Terminating Windows NT Logon/Logoff Manager
[11/01/2007, 23:43:49] - Re-enabling Automatic Shell Restart
[11/01/2007, 23:43:50] - File to disable: C:\WINDOWS\system32\ysnzpmfv.dll
[11/01/2007, 23:43:50] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:55] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:57] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[11/01/2007, 23:43:58] - Deleting ATLEvents/MSEvents Registry entries
[11/01/2007, 23:43:58] - Removing HKLM\...\Winlogon\Notify\ysnzpmfv
[11/01/2007, 23:43:58] - Searching for Browser Helper Objects:
[11/01/2007, 23:43:58] - BHO 1: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[11/01/2007, 23:43:58] - BHO 2: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[11/01/2007, 23:43:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:58] - No filename found. Continuing.
[11/01/2007, 23:43:59] - BHO 3: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\jfpyttjr
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\jfpyttjr, continuing.
[11/01/2007, 23:43:59] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:59] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:59] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:59] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:59] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:59] - Finishing up...
[11/01/2007, 23:44:00] - A restart is needed.
[11/01/2007, 23:44:04] - Attempting to Restart via STOP error (Blue Screen!)
[11/02/2007, 16:47:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\BRICE BONADEI\Mes documents\Brice BONADEI\virtumundobegone.exe" )
[11/02/2007, 16:47:21] - User choose NOT to continue. Exiting...
[11/01/2007, 23:43:59] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/01/2007, 23:43:59] - BHO 5: {99006350-D474-46C6-AE5B-F5492BEB8BCB} ()
[11/01/2007, 23:43:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/01/2007, 23:43:59] - Checking for HKLM\...\Winlogon\Notify\pmnlk
[11/01/2007, 23:43:59] - Key not found: HKLM\...\Winlogon\Notify\pmnlk, continuing.
[11/01/2007, 23:43:59] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/01/2007, 23:43:59] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[11/01/2007, 23:43:59] - Finished Searching Browser Helper Objects
[11/01/2007, 23:43:59] - Finishing up...
[11/01/2007, 23:44:00] - A restart is needed.
[11/01/2007, 23:44:04] - Attempting to Restart via STOP error (Blue Screen!)
[11/02/2007, 16:47:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\BRICE BONADEI\Mes documents\Brice BONADEI\virtumundobegone.exe" )
[11/02/2007, 16:47:21] - User choose NOT to continue. Exiting...
Non se n'est pas le bon rapport, tu ma poster le rapport VirtumundoBeGone qui date de janvier ?
le rapport se trouve dans C:\vundofix.txt
@+
le rapport se trouve dans C:\vundofix.txt
@+
Bonjour,
pi etre que cé ca ::::::::::::::::::
VundoFix V6.5.11
Checking Java version...
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Scan started at 00:16:23 02/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\jfpyttjr.dll
C:\WINDOWS\system32\ysnzpmfv.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\jfpyttjr.dll
C:\WINDOWS\system32\jfpyttjr.dll Has been deleted!
Performing Repairs to the registry.
Done!
pi etre que cé ca ::::::::::::::::::
VundoFix V6.5.11
Checking Java version...
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Scan started at 00:16:23 02/11/2007
Listing files found while scanning....
C:\WINDOWS\system32\jfpyttjr.dll
C:\WINDOWS\system32\ysnzpmfv.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\jfpyttjr.dll
C:\WINDOWS\system32\jfpyttjr.dll Has been deleted!
Performing Repairs to the registry.
Done!
maintenant Télécharge Combofix (par sUBs) sur ton Bureau.
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double clique combofix.exe.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.
Le rapport se trouve ici : C:\Combofix.txt
@+
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double clique combofix.exe.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.
Le rapport se trouve ici : C:\Combofix.txt
@+