Pub hopelessromantic me harcele

Résolu/Fermé
zizou00 Messages postés 12 Date d'inscription mardi 20 novembre 2007 Statut Membre Dernière intervention 27 novembre 2007 - 21 nov. 2007 à 23:45
zizou00 Messages postés 12 Date d'inscription mardi 20 novembre 2007 Statut Membre Dernière intervention 27 novembre 2007 - 27 nov. 2007 à 18:45
Bonjour,
voilà une fenetre pup hopelessromantic.com/pop.php apparait sur mon ecran chaque fois que je me connecte.c'est vraiment trés génant.si quelqu'un pourrait m'aider pour la supprimer.voilà le rapport hajackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:43:27, on 21/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Megatec\UPSilon 2000\RupsMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\system32\UMonit2K.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Menara\dslmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Megatec\UPSilon 2000\Monw32.exe
C:\HAD\PTW.EXE
C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Megatec\UPSilon 2000\USBMate.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\eMule plus\eMule.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.menara.ma/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\ftcleokj.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINDOWS\system32\UMonit2K.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rupsmon Daemon.lnk = ?
O4 - Global Startup: أوقات الصلاة.lnk = C:\HAD\PTW.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.coupdepoucepc.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A669C16-DACF-4302-A677-613A820D3D1A}: NameServer = 212.217.0.14 196.217.246.210
O18 - Protocol: bw+0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw+0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw-0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw-0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw00 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw00s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw10 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw10s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw20 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw20s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw30 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw30s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw40 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw40s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw50 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw50s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw60 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw60s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw70 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw70s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw80 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw80s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw90 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bw90s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwa0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwa0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwb0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwb0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwc0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwc0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwd0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwd0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwe0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwe0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwf0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwf0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
O18 - Protocol: bwg0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwg0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwh0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwh0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwi0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwi0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwj0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwj0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwk0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwk0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwl0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwl0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwm0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwm0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwn0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwn0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwo0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwo0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwp0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwp0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwq0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwq0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwr0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwr0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bws0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bws0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwt0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwt0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwu0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwu0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwv0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwv0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bww0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bww0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwx0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwx0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwy0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwy0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwz0 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: bwz0s - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: offline-8876480 - {10578EE4-6978-445A-8ECF-ED9599CE20BD} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Rupsmon - Mega System Technologies, Inc. - C:\Program Files\Megatec\UPSilon 2000\RupsMon.exe
O23 - Service: USBMate - Mega Corp. - C:\Program Files\Megatec\UPSilon 2000\USBMate.exe
A voir également:

23 réponses

zizou00 Messages postés 12 Date d'inscription mardi 20 novembre 2007 Statut Membre Dernière intervention 27 novembre 2007
26 nov. 2007 à 21:02
bonsoir ^^Marie^^ voilà j'ai fais ce qui a été demandé il y a deux rapports dans OTMovelt/MovedFiles les Voilà:
C:\WINDOWS\SYSTEM32\FMDQAEBJ.EXE moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\rntcfrbj.dll
C:\WINDOWS\system32\rntcfrbj.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\rntcfrbj.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\xgirkppw.dll
C:\WINDOWS\system32\xgirkppw.dll NOT unregistered.
C:\WINDOWS\system32\xgirkppw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\KHDQFGHF.DLL
C:\WINDOWS\SYSTEM32\KHDQFGHF.DLL NOT unregistered.
C:\WINDOWS\SYSTEM32\KHDQFGHF.DLL moved successfully.

Created on 11/22/2007 23:07:48
et l"autre c"est:

C:\Program Files\Navilog1\Backupnavi moved successfully.
C:\Program Files\Navilog1 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\xgirkppw.dll
C:\WINDOWS\system32\xgirkppw.dll NOT unregistered.
C:\WINDOWS\system32\xgirkppw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cprthiur.dll
C:\WINDOWS\system32\cprthiur.dll NOT unregistered.
C:\WINDOWS\system32\cprthiur.dll moved successfully.
C:\WINDOWS\system32\luqiwdag.ini moved successfully.
File/Folder C:\Program Files\XoftSpySE not found.
C:\WINDOWS\system32\SrchSTS.exe moved successfully.
C:\WINDOWS\system32\dumphive.exe moved successfully.
C:\WINDOWS\system32\anhhgwoc.ini moved successfully.
C:\WINDOWS\system32\xgwnoqdc.ini moved successfully.
C:\WINDOWS\system32\ywgfkcyb.ini moved successfully.
C:\WINDOWS\system32\qeswupfm.ini moved successfully.
C:\WINDOWS\system32\mhqbgktw.ini moved successfully.
C:\WINDOWS\system32\lojyqwdn.ini moved successfully.
C:\WINDOWS\system32\jdibexat.ini moved successfully.
C:\WINDOWS\system32\ylygpqyh.ini moved successfully.
C:\WINDOWS\system32\rgucsmhh.ini moved successfully.
C:\WINDOWS\system32\juhbfmwv.ini moved successfully.
C:\WINDOWS\system32\cuprojhl.ini moved successfully.
C:\WINDOWS\system32\gsdhfnti.ini moved successfully.
C:\WINDOWS\system32\kmdcnnwd.ini moved successfully.
C:\WINDOWS\system32\swlrypvy.ini moved successfully.
C:\WINDOWS\system32\ajkkvehf.ini moved successfully.
C:\WINDOWS\system32\wxbaospq.ini moved successfully.
C:\WINDOWS\system32\mjdollxs.ini moved successfully.
C:\WINDOWS\system32\puwcdrex.ini moved successfully.
C:\WINDOWS\system32\kyacuobx.ini moved successfully.
C:\WINDOWS\system32\cffxrhjb.ini moved successfully.

Created on 11/26/2007 19:55:28
0
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
27 nov. 2007 à 15:23
0
zizou00 Messages postés 12 Date d'inscription mardi 20 novembre 2007 Statut Membre Dernière intervention 27 novembre 2007
27 nov. 2007 à 18:45
resalut ^^Marie^^ et merci bcq voilà ce qui est demandé a été fait voilà le rapport de cambofix:
ComboFix 07-11-19.4 - Administrateur 2007-11-27 17:30:02.3 - NTFSx86 MINIMAL

Running from: C:\Downloads\Software\ComboFix.exe
.

((((((((((((((((((((((((((((( Fichiers créés 2007-10-27 to 2007-11-27 ))))))))))))))))))))))))))))))))))))
.

2007-11-26 23:59 <REP> d-------- C:\Program Files\iPod
2007-11-26 23:58 <REP> d-------- C:\Program Files\iTunes
2007-11-24 15:56 <REP> d-------- C:\Program Files\iTunes(3)
2007-11-24 15:56 <REP> d-------- C:\Program Files\iPod(3)
2007-11-24 15:53 <REP> d-------- C:\Program Files\QuickTime
2007-11-24 12:41 <REP> d-------- C:\Documents and Settings\HP_Propriلtaire\Bureau
2007-11-24 08:48 <REP> d-------- C:\Program Files\Crawler
2007-11-23 17:12 85,056 --a------ C:\WINDOWS\system32\jndfpybu.dll
2007-11-23 17:12 954 ---hs---- C:\WINDOWS\system32\ubypfdnj.ini
2007-11-23 16:59 <REP> d-------- C:\Program Files\HardwareDetection
2007-11-22 23:40 <REP> d-------- C:\Program Files\Enigma Software Group
2007-11-22 18:37 <REP> d-------- C:\Program Files\Panda Security
2007-11-21 22:20 <REP> d-------- C:\Program Files\Trend Micro
2007-11-21 21:43 <REP> d-------- C:\Program Files\MSBuild
2007-11-21 21:41 <REP> d-------- C:\Program Files\Microsoft.NET
2007-11-21 21:37 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-11-21 21:36 <REP> d-------- C:\WINDOWS\SHELLNEW
2007-11-21 21:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-21 21:32 <REP> dr-h----- C:\MSOCache
2007-11-21 20:45 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2007-11-21 20:24 294 ---hs---- C:\WINDOWS\system32\wppkrigx.ini
2007-11-21 17:25 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-11-20 01:30 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-11-20 01:30 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-11-20 01:30 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-11-20 01:30 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-11-20 01:30 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-11-20 01:30 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intervideo
2007-11-20 01:30 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2007-11-20 01:14 4,940 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-20 01:12 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-11-20 01:12 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-11-18 21:47 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\gtk-2.0
2007-11-17 23:08 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\.thumbnails
2007-11-17 23:08 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\.thumbnails
2007-11-17 23:06 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\.gimp-2.4
2007-11-17 23:06 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\.gimp-2.4
2007-11-17 23:05 <REP> d-------- C:\Program Files\GIMP-2.0
2007-11-17 22:16 <REP> d-------- C:\Program Files\iPod(2)
2007-11-17 22:15 <REP> d-------- C:\Program Files\iTunes(2)
2007-11-17 22:12 <REP> d-------- C:\Program Files\QuickTime(2)
2007-11-16 23:43 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Sony Corporation
2007-11-16 23:42 <REP> d-------- C:\Drivers
2007-11-16 23:42 299,923 --a------ C:\WINDOWS\system32\drivers\sonyhcs.sys
2007-11-16 23:42 102,220 --a------ C:\WINDOWS\system32\drivers\sonypvs1.sys
2007-11-16 23:42 53,248 --a------ C:\WINDOWS\system32\SONYHCY.DLL
2007-11-16 23:42 38,739 --a------ C:\WINDOWS\system32\drivers\sonyhcc.sys
2007-11-16 23:42 6,097 --a------ C:\WINDOWS\system32\drivers\sonyhcb.sys
2007-11-16 23:42 3,654 --a------ C:\WINDOWS\system32\drivers\Sonyhcp.dll
2007-11-16 23:41 118,520 --a------ C:\WINDOWS\system32\PxInsI64.exe
2007-11-16 23:41 115,960 --a------ C:\WINDOWS\system32\PxCpyI64.exe
2007-11-16 23:41 2,560 --a------ C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-16 23:41 2,432 --a------ C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-16 23:39 <REP> d-------- C:\Program Files\Sony
2007-11-10 22:41 714 ---hs---- C:\WINDOWS\system32\uoxluman.ini
2007-11-10 22:10 <REP> d-------- C:\Program Files\PC Sync Manager
2007-11-08 22:21 78,464 --a------ C:\WINDOWS\system32\drivers\usbvideo.sys
2007-11-08 22:21 78,464 --a--c--- C:\WINDOWS\system32\dllcache\usbvideo.sys
2007-11-08 22:21 20,992 --a------ C:\WINDOWS\system32\dshowext.ax
2007-11-08 22:21 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2007-11-08 00:58 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-11-08 00:58 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2007-11-03 01:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Acronis
2007-11-03 01:26 <REP> d-------- C:\Program Files\Fichiers communs\Acronis
2007-11-03 01:26 <REP> d-------- C:\Program Files\Acronis
2007-11-02 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Micro Application
2007-11-02 22:58 395,744 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2007-11-02 22:58 114,048 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2007-11-02 22:58 39,264 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-10-31 01:03 2,138,112 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2007-10-31 01:03 2,138,112 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-10-30 22:09 <REP> d-------- C:\Program Files\LIUtilities
2007-10-27 21:58 <REP> d-------- C:\Program Files\BillP Studios
2007-10-27 21:58 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\WinPatrol
2007-10-27 19:55 694,264 ---hs---- C:\WINDOWS\system32\qwacfvoh.ini
2007-10-27 18:32 <REP> d-------- C:\Program Files\Fichiers communs\PC Tools
2007-10-27 00:27 <REP> d-------- C:\Program Files\Agnitum
2007-10-27 00:16 <REP> d-------- C:\Program Files\SpyBlocker Software
2007-10-27 00:16 796,672 --a------ C:\WINDOWS\GPInstall.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-27 17:26 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Free Download Manager
2007-11-27 17:19 --------- d---a-w C:\Program Files\Al Muhaddith
2007-11-26 23:56 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
2007-11-24 08:43 --------- d-----w C:\Program Files\a-squared Free
2007-11-23 23:00 --------- d-----w C:\Program Files\eMule plus
2007-11-21 21:43 --------- d-----w C:\Program Files\Microsoft Works
2007-11-18 21:45 2,097,152,000 ----a-w C:\timeshift.dat
2007-11-16 23:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 22:55 --------- d-----w C:\Program Files\Modèles Météo - GFS
2007-10-31 22:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-31 18:00 --------- d-----w C:\Program Files\WinUpdater
2007-10-31 01:34 --------- d-----w C:\Program Files\Menara
2007-10-30 22:17 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-27 19:57 --------- d-----w C:\Program Files\Nokia
2007-10-27 19:56 --------- d-----w C:\Program Files\Fichiers communs\PCSuite
2007-10-27 19:02 --------- d-----w C:\Program Files\Free Download Manager
2007-10-27 09:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-27 00:16 --------- d-----w C:\Program Files\Trojan Remover
2007-10-25 16:43 8,516,608 ----a-w C:\WINDOWS\system32\shell32(4).dll
2007-10-25 16:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 16:05 93,264 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 16:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 16:01 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 15:58 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-25 15:24 815,480 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-10-25 15:14 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-10-24 22:44 --------- d-----w C:\Program Files\Java
2007-10-24 22:32 --------- d-----w C:\Program Files\Google
2007-10-24 21:31 --------- d-----w C:\Program Files\Yahoo!
2007-10-24 21:31 --------- d-----w C:\Program Files\Webteh
2007-10-24 21:31 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Webroot
2007-10-24 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-10-24 18:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2007-10-20 21:24 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2007-10-20 21:06 --------- d-----w C:\Program Files\Fichiers communs\Nero
2007-10-20 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-10-20 20:00 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Nero
2007-10-20 19:54 --------- d-----w C:\Program Files\Nero
2007-10-04 21:10 --------- d-----w C:\Program Files\Claris Corp
2007-10-01 21:02 --------- d-----w C:\Program Files\eMule
.

((((((((((((((((((((((((((((( snapshot@2007-11-24_15.24.37,17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-26 23:59:43 102,400 ----a-r C:\WINDOWS\Installer\{E3FEE4E7-4488-4A3F-A6BD-13745936EADB}\iTunesIco.exe
+ 2007-10-31 14:09:14 30,464 -c--a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_4351B7DAFF62FD33510D77DFAE3CF8CC82517571\usbaapl.sys
- 2007-11-23 17:00:14 1,523,168 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2007-11-26 21:53:13 653,520 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1337e96b-ecca-4e97-8a25-8c7f824a55b0}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 10:00]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 13:31]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NeroHomeFirstStart"="C:\Program Files\Fichiers communs\Ahead\Lib\NMFirstStart.exe" [2006-10-09 11:08]
"SpywareTerminatorScan"="C:\Program Files\Spyware Terminator\SpywareTerminator.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 15:04]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 17:43]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 19:43]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 16:06 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 17:58 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-24 21:10]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 20:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 20:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"Dit"="Dit.exe" [2002-05-20 19:47 C:\WINDOWS\Dit.exe]
"UMonit"="C:\WINDOWS\system32\UMonit.exe" [2003-03-10 03:20]
"Gene USB Monitor"="C:\WINDOWS\system32\UMonit2K.exe" [2002-12-17 09:58]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2004-05-20 08:47]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-02-25 20:36]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 00:05 C:\WINDOWS\ALCWZRD.EXE]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 15:20]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-18 17:58]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-18 18:02]
"Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2006-10-17 11:47]
"3c5589a9"="C:\WINDOWS\system32\jndfpybu.dll" [2007-11-23 17:12]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]

C:\Documents and Settings\HP_Propri‚taire\Bureau\Raccourcis Bureau non utilis‚s\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-09-23 00:57:27]
HDDlife.lnk - C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe [2006-03-20 11:07:22]
Outil de d‚tection de support Picture Motion Browser.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-11-16 23:39:27]
Webshots.lnk - C:\Program Files\Webshots\WebshotsTray.exe [2006-02-20 16:03:37]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\Menara\dslmon.exe [2007-02-01 20:58:12]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 04:31:38]
Rupsmon Daemon.lnk - C:\Program Files\Megatec\UPSilon 2000\Monw32.exe [2006-02-20 15:41:29]
ڑيçں¢ ںé­éں،.lnk - C:\HAD\PTW.EXE [2003-01-08 03:05:38]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zsgzxphy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"PCTVRemote"=C:\Program Files\Pinnacle\Pinnacle PCTV Sat\Remote\Remoterm.exe


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - ADILOADER
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-09-13 21:50:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-26 20:01:37 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-27 17:33:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-27 17:34:30
C:\ComboFix2.txt ... 2007-11-24 15:25
.
--- E O F ---
0