Fenetre "em pc internet" s'ouvre seul
Résolu
myps19
Messages postés
31
Statut
Membre
-
Emilie35 -
Emilie35 -
Bonjour,
J'ai un probleme quand je surfe sur internet, une voir plusieurs fenêtres de pubs s'ouvrent parfois. J'aimerais trouver un moyen de les éradiquer. Les antivirus, antispyware et pare feu ne mènent à rien. Merci d'avance pour votre aide.
J'ai un probleme quand je surfe sur internet, une voir plusieurs fenêtres de pubs s'ouvrent parfois. J'aimerais trouver un moyen de les éradiquer. Les antivirus, antispyware et pare feu ne mènent à rien. Merci d'avance pour votre aide.
A voir également:
- Fenetre "em pc internet" s'ouvre seul
- Reinitialiser pc - Guide
- Pc lent - Guide
- Test performance pc - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Forcer demarrage pc - Guide
59 réponses
as tu redémarré depuis OTMoveIT?
si non, fais le et poste un nouveau Blacklight, je vaux être certain que les fichhiers ont bien été supprimés
ton PC rame dis tu?
si non, fais le et poste un nouveau Blacklight, je vaux être certain que les fichhiers ont bien été supprimés
ton PC rame dis tu?
Oui mon ordi rame un peu depuis!!
Voici le post de blacklight:
02/16/08 21:31:08 [Info]: BlackLight Engine 1.0.67 initialized
02/16/08 21:31:08 [Info]: OS: 5.1 build 2600 (Service Pack 2)
02/16/08 21:31:08 [Note]: 7019 4
02/16/08 21:31:08 [Note]: 7005 0
02/16/08 21:31:47 [Note]: 7006 0
02/16/08 21:31:50 [Note]: 7011 1328
02/16/08 21:31:50 [Note]: 7026 0
02/16/08 21:31:50 [Note]: 7026 0
02/16/08 21:32:11 [Note]: FSRAW library version 1.7.1024
02/16/08 21:45:33 [Note]: 7007 0
Encore merci
Voici le post de blacklight:
02/16/08 21:31:08 [Info]: BlackLight Engine 1.0.67 initialized
02/16/08 21:31:08 [Info]: OS: 5.1 build 2600 (Service Pack 2)
02/16/08 21:31:08 [Note]: 7019 4
02/16/08 21:31:08 [Note]: 7005 0
02/16/08 21:31:47 [Note]: 7006 0
02/16/08 21:31:50 [Note]: 7011 1328
02/16/08 21:31:50 [Note]: 7026 0
02/16/08 21:31:50 [Note]: 7026 0
02/16/08 21:32:11 [Note]: FSRAW library version 1.7.1024
02/16/08 21:45:33 [Note]: 7007 0
Encore merci
Télécharge ce programme puis double clic dessus (ferme ton antivirus s'il te détecte quoi que ce soit)
http://www.suspectfile.com/systemscan/
* Coche uniquement cette case, décoche tout le reste :
- Recent Files, 30 days
Puis clic sur scan now, soit patient.
Une fois qu'il aura terminé, un rapport va s'ouvrir, copie et colle son contenu ici et vérifie qu'il soit bien en entier, si besoin crée deux messages.
Remets aussi un log Hijackthis
http://www.suspectfile.com/systemscan/
* Coche uniquement cette case, décoche tout le reste :
- Recent Files, 30 days
Puis clic sur scan now, soit patient.
Une fois qu'il aura terminé, un rapport va s'ouvrir, copie et colle son contenu ici et vérifie qu'il soit bien en entier, si besoin crée deux messages.
Remets aussi un log Hijackthis
ok le hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:53:47, on 16/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SopCast\SopCast.exe
C:\Program Files\SopCast\adv\SopAdver.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4} - (no file)
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [susqhjcqr] c:\documents and settings\ordi\local settings\application data\susqhjcqr.exe susqhjcqr
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra 'Tools' menuitem: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://regulus.upmf-grenoble.fr/qp2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:53:47, on 16/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SopCast\SopCast.exe
C:\Program Files\SopCast\adv\SopAdver.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4} - (no file)
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [susqhjcqr] c:\documents and settings\ordi\local settings\application data\susqhjcqr.exe susqhjcqr
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra 'Tools' menuitem: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://regulus.upmf-grenoble.fr/qp2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Et le poste du scan:
SystemScan - www.suspectfile.com - ver. 3.5.0 (code: holifay & bReAkdOWn)
Running on: Windows XP HOME Edition, Service Pack 2 (2600.5.1)
System directory: C:\WINDOWS
SystemScan file: C:\Downloads\sys64012.exe
Running in: User mode
Date: 16/02/2008
Time: 21:58:17
Output limited to:
-Recent files
===================== Recent files (30 days old) =====================
----- recent files in C:\
31/01/2008 17:49:49 (DIR) 0 byte 16 days old -- Documents and Settings
15/02/2008 16:16:15 (DIR) 0 byte 1 days old -- Config.Msi
15/02/2008 16:24:44 216 byte 1 days old -- boot.ini
16/02/2008 14:44:58 74 byte 0 days old -- fixnavi.txt
16/02/2008 16:42:55 (DIR) 0 byte 0 days old -- Navipromo
16/02/2008 17:46:02 1498 byte 0 days old -- Navipromo.txt
16/02/2008 17:47:12 1580 byte 0 days old -- egd.txt
16/02/2008 18:32:48 (DIR) 0 byte 0 days old -- Program Files
16/02/2008 19:40:40 805 byte 0 days old -- rollback.ini
16/02/2008 20:12:46 (DIR) 0 byte 0 days old -- _OTMoveIt
16/02/2008 20:16:19 704643072 byte 0 days old -- pagefile.sys
16/02/2008 20:22:48 (DIR) 0 byte 0 days old -- WINDOWS
16/02/2008 21:56:01 (DIR) 0 byte 0 days old -- Downloads
16/02/2008 21:58:17 (DIR) 0 byte 0 days old -- suspectfile
----- recent files in C:\WINDOWS\
18/01/2008 16:11:36 (DIR) 0 byte 29 days old -- network diagnostic
18/01/2008 19:14:36 115200 byte 29 days old -- snap.dat
19/01/2008 19:44:05 151 byte 28 days old -- PhotoSnapViewer.INI
08/02/2008 14:40:23 691545 byte 8 days old -- unins000.exe
08/02/2008 14:40:58 3456 byte 8 days old -- unins000.dat
12/02/2008 16:26:04 (DIR) 0 byte 4 days old -- Minidump
13/02/2008 12:02:31 (DIR) 0 byte 3 days old -- $hf_mig$
13/02/2008 15:03:26 (DIR) 0 byte 3 days old -- ie7updates
13/02/2008 19:05:54 (DIR) 0 byte 3 days old -- inf
13/02/2008 19:33:24 (DIR) 0 byte 3 days old -- WinSxS
13/02/2008 19:53:30 (DIR) 0 byte 3 days old -- assembly
13/02/2008 19:53:50 (DIR) 0 byte 3 days old -- Microsoft.NET
15/02/2008 16:16:16 (DIR) 0 byte 1 days old -- Installer
15/02/2008 16:24:01 (DIR) 0 byte 1 days old -- pss
15/02/2008 16:24:44 562 byte 1 days old -- win.ini
15/02/2008 16:24:44 227 byte 1 days old -- system.ini
16/02/2008 14:38:28 116 byte 0 days old -- NeroDigital.ini
16/02/2008 15:30:07 (DIR) 0 byte 0 days old -- Debug
16/02/2008 15:34:21 (DIR) 0 byte 0 days old -- Downloaded Program Files
16/02/2008 17:36:56 32522 byte 0 days old -- SchedLgU.Txt
16/02/2008 17:38:58 234292 byte 0 days old -- ntbtlog.txt
16/02/2008 19:06:58 8207 byte 0 days old -- setupapi.log
16/02/2008 19:53:03 (DIR) 0 byte 0 days old -- system32
16/02/2008 20:16:22 2048 byte 0 days old -- bootstat.dat
16/02/2008 20:17:08 50 byte 0 days old -- wiaservc.log
16/02/2008 20:17:11 159 byte 0 days old -- wiadebug.log
16/02/2008 20:17:13 1391494 byte 0 days old -- WindowsUpdate.log
16/02/2008 20:17:30 0 byte 0 days old -- 0.log
16/02/2008 20:43:29 (DIR) 0 byte 0 days old -- Temp
16/02/2008 21:54:55 (DIR) 0 byte 0 days old -- Internet Logs
16/02/2008 21:58:15 (DIR) 0 byte 0 days old -- Prefetch
----- recent files in C:\WINDOWS\Downloaded Program Files\
----- recent files in C:\WINDOWS\system\
----- recent files in C:\WINDOWS\system32\
26/01/2008 10:46:15 (DIR) 0 byte 21 days old -- Macromed
29/01/2008 15:08:40 (DIR) 0 byte 18 days old -- CatRoot
05/02/2008 00:09:46 18214008 byte 11 days old -- MRT.exe
13/02/2008 15:04:47 (DIR) 0 byte 3 days old -- dllcache
13/02/2008 19:34:15 77278 byte 3 days old -- perfc00C.dat
13/02/2008 19:34:15 988696 byte 3 days old -- PerfStringBackup.INI
13/02/2008 19:34:15 474734 byte 3 days old -- perfh00C.dat
13/02/2008 19:34:15 406464 byte 3 days old -- perfh009.dat
13/02/2008 19:34:15 63664 byte 3 days old -- perfc009.dat
15/02/2008 13:36:08 4212 byte 1 days old -- zllictbl.dat
15/02/2008 18:41:57 (DIR) 0 byte 1 days old -- ZoneLabs
16/02/2008 16:34:08 (DIR) 0 byte 0 days old -- CatRoot2
16/02/2008 16:50:03 (DIR) 0 byte 0 days old -- bfubackups
16/02/2008 19:06:58 (DIR) 0 byte 0 days old -- drivers
16/02/2008 20:18:16 358830 byte 0 days old -- vsconfig.xml
16/02/2008 20:19:50 13646 byte 0 days old -- wpa.dbl
----- recent files in C:\WINDOWS\system32\drivers\
08/02/2008 15:13:52 (DIR) 0 byte 8 days old -- etc
16/02/2008 20:15:38 58328 byte 0 days old -- fidbox.idx
16/02/2008 21:58:06 4316960 byte 0 days old -- fidbox.dat
----- recent files in C:\WINDOWS\temp\
16/02/2008 17:52:41 256 byte 0 days old -- ZLT00916.TMP
16/02/2008 17:52:41 256 byte 0 days old -- ZLT04aab.TMP
16/02/2008 17:53:10 16384 byte 0 days old -- Perflib_Perfdata_708.dat
16/02/2008 18:13:06 256 byte 0 days old -- ZLT018b3.TMP
16/02/2008 18:13:06 256 byte 0 days old -- ZLT018b6.TMP
16/02/2008 19:06:26 256 byte 0 days old -- ZLT04188.TMP
16/02/2008 19:06:26 256 byte 0 days old -- ZLT0068d.TMP
16/02/2008 19:06:36 16384 byte 0 days old -- Perflib_Perfdata_714.dat
16/02/2008 19:53:11 256 byte 0 days old -- ZLT06550.TMP
16/02/2008 19:53:11 256 byte 0 days old -- ZLT0654c.TMP
16/02/2008 19:53:22 16384 byte 0 days old -- Perflib_Perfdata_704.dat
16/02/2008 20:16:24 255 byte 0 days old -- WGAErrLog.txt
16/02/2008 20:16:26 256 byte 0 days old -- ZLT0771b.TMP
16/02/2008 20:16:26 256 byte 0 days old -- ZLT05b98.TMP
16/02/2008 20:16:54 16384 byte 0 days old -- Perflib_Perfdata_750.dat
16/02/2008 20:20:47 409 byte 0 days old -- WGANotify.settings
16/02/2008 21:58:25 (DIR) 0 byte 0 days old -- _avast4_
----- recent files in C:\Program Files\
29/01/2008 17:20:05 (DIR) 0 byte 18 days old -- Cyanide
30/01/2008 22:11:05 (DIR) 0 byte 17 days old -- StreamerOne
02/02/2008 13:40:48 (DIR) 0 byte 14 days old -- GF38_Immersive_Stadium
08/02/2008 14:46:05 (DIR) 0 byte 8 days old -- Spybot - Search & Destroy
10/02/2008 21:11:12 (DIR) 0 byte 6 days old -- TVAnts
12/02/2008 17:40:19 (DIR) 0 byte 4 days old -- a-squared Free
12/02/2008 19:07:07 (DIR) 0 byte 4 days old -- Zone Labs
13/02/2008 15:03:51 (DIR) 0 byte 3 days old -- Internet Explorer
14/02/2008 14:50:46 (DIR) 0 byte 2 days old -- Spyware Doctor
15/02/2008 15:54:30 (DIR) 0 byte 1 days old -- Trend Micro
15/02/2008 16:18:44 (DIR) 0 byte 1 days old -- Gamenext
15/02/2008 18:07:55 (DIR) 0 byte 1 days old -- eMule
16/02/2008 15:18:01 (DIR) 0 byte 0 days old -- Navilog1
16/02/2008 18:33:56 (DIR) 0 byte 0 days old -- a-squared Anti-Malware
----- recent files in C:\Program Files\Fichiers communs\
16/02/2008 18:33:07 (DIR) 0 byte 0 days old -- Adobe
----- recent files in C:\Documents and Settings\Ordi\Application Data\
23/01/2008 21:39:40 (DIR) 0 byte 24 days old -- TVU Networks
25/01/2008 12:44:47 (DIR) 0 byte 22 days old -- Adobe
12/02/2008 19:24:52 (DIR) 0 byte 4 days old -- MailFrontier
15/02/2008 16:16:16 (DIR) 0 byte 1 days old -- Microsoft
16/02/2008 17:41:02 (DIR) 0 byte 0 days old -- OpenOffice.org2
----- recent files in C:\DOCUME~1\Ordi\LOCALS~1\Temp\
16/02/2008 17:57:42 1342 byte 0 days old -- MAR11.tmp
16/02/2008 17:57:49 1285 byte 0 days old -- MAR12.tmp
16/02/2008 17:58:18 16384 byte 0 days old -- ~DF4997.tmp
16/02/2008 17:59:16 114688 byte 0 days old -- ~DF8D15.tmp
16/02/2008 17:59:17 512 byte 0 days old -- ~DFAAB8.tmp
16/02/2008 18:00:04 16384 byte 0 days old -- ~DFEC39.tmp
16/02/2008 18:00:05 114688 byte 0 days old -- ~DFF193.tmp
16/02/2008 18:00:05 512 byte 0 days old -- ~DFF3CF.tmp
16/02/2008 18:01:19 109 byte 0 days old -- STS14.tmp
16/02/2008 18:10:25 (DIR) 0 byte 0 days old -- Google Toolbar
16/02/2008 18:20:19 16384 byte 0 days old -- ~DFEF68.tmp
16/02/2008 18:20:22 1342 byte 0 days old -- MAR1.tmp
16/02/2008 18:20:26 1285 byte 0 days old -- MAR2.tmp
16/02/2008 18:21:15 16384 byte 0 days old -- ~DF7B6.tmp
16/02/2008 18:21:45 109 byte 0 days old -- STS4.tmp
16/02/2008 18:34:56 (DIR) 0 byte 0 days old -- {4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
16/02/2008 19:06:17 (DIR) 0 byte 0 days old -- ~nsu.tmp
16/02/2008 19:09:50 16384 byte 0 days old -- ~DF7FAF.tmp
16/02/2008 19:59:41 1342 byte 0 days old -- MAR3.tmp
16/02/2008 19:59:43 16384 byte 0 days old -- ~DF5930.tmp
16/02/2008 19:59:49 1285 byte 0 days old -- MAR4.tmp
16/02/2008 20:02:14 109 byte 0 days old -- STS6.tmp
16/02/2008 20:10:36 (DIR) 0 byte 0 days old -- bc_tmp
16/02/2008 20:10:48 (DIR) 0 byte 0 days old -- bc_cache
16/02/2008 20:14:36 8979 byte 0 days old -- hpodvd09.log
16/02/2008 20:19:19 (DIR) 0 byte 0 days old -- WPDNSE
16/02/2008 20:22:33 1342 byte 0 days old -- MAR14.tmp
16/02/2008 20:22:36 1285 byte 0 days old -- MAR15.tmp
16/02/2008 20:22:48 16384 byte 0 days old -- ~DFB504.tmp
16/02/2008 20:23:44 114688 byte 0 days old -- ~DFBF1.tmp
16/02/2008 20:23:44 512 byte 0 days old -- ~DFD5C.tmp
16/02/2008 20:23:51 16384 byte 0 days old -- ~DFD376.tmp
16/02/2008 20:24:02 512 byte 0 days old -- ~DF1DC1.tmp
16/02/2008 20:24:02 114688 byte 0 days old -- ~DF1C92.tmp
16/02/2008 20:24:03 109 byte 0 days old -- STS17.tmp
16/02/2008 20:29:21 (DIR) 0 byte 0 days old -- MessengerCache
16/02/2008 20:29:34 1020 byte 0 days old -- jusched.log
16/02/2008 20:56:21 835584 byte 0 days old -- ~DF78D9.tmp
16/02/2008 21:31:09 (DIR) 0 byte 0 days old -- F-Secure
16/02/2008 21:55:50 (DIR) 0 byte 0 days old -- _avast4_
16/02/2008 21:57:13 25 byte 0 days old -- systemscan.ini
16/02/2008 21:57:22 16384 byte 0 days old -- ~DF6677.tmp
16/02/2008 21:57:22 16384 byte 0 days old -- ~DF6689.tmp
16/02/2008 21:57:25 (DIR) 0 byte 0 days old -- nsf27.tmp
16/02/2008 21:57:25 (DIR) 0 byte 0 days old -- nsa28.tmp
==========================================
Scan completed in 0,4 minutes
End of report
~~~~~~~~~~~~~~~~~~~~~-----CREDITS-----~~~~~~~~~~~~~~~~~~~~~
SystemScan uses some freeware tools that remain property of their authors:
* SteelWerX Registry Console Tool, Who Am I (Bobby Flekman: www.xs4all.nl/~fstaal01) --> "Registry scan", "PC accounts "
* dumphive (Markus Stephany)--> "Registry scan"
* Listdlls (M.Russinovich, B.Cogswell: www.sysinternals.com) --> "Loaded modules"
* Catchme & MBR Rootkit detector (gmer: www.gmer.net) --> "Hidden objects", "Alternate Data Streams" & "Master Boot Record"
---> NOTE: SystemScan integrates "The Avenger" from Swandog46 (http://swandog46.geekstogo.com) to allow you to remove malwares found in this log
Thanks to all of them for their hard work
SystemScan - www.suspectfile.com - ver. 3.5.0 (code: holifay & bReAkdOWn)
Running on: Windows XP HOME Edition, Service Pack 2 (2600.5.1)
System directory: C:\WINDOWS
SystemScan file: C:\Downloads\sys64012.exe
Running in: User mode
Date: 16/02/2008
Time: 21:58:17
Output limited to:
-Recent files
===================== Recent files (30 days old) =====================
----- recent files in C:\
31/01/2008 17:49:49 (DIR) 0 byte 16 days old -- Documents and Settings
15/02/2008 16:16:15 (DIR) 0 byte 1 days old -- Config.Msi
15/02/2008 16:24:44 216 byte 1 days old -- boot.ini
16/02/2008 14:44:58 74 byte 0 days old -- fixnavi.txt
16/02/2008 16:42:55 (DIR) 0 byte 0 days old -- Navipromo
16/02/2008 17:46:02 1498 byte 0 days old -- Navipromo.txt
16/02/2008 17:47:12 1580 byte 0 days old -- egd.txt
16/02/2008 18:32:48 (DIR) 0 byte 0 days old -- Program Files
16/02/2008 19:40:40 805 byte 0 days old -- rollback.ini
16/02/2008 20:12:46 (DIR) 0 byte 0 days old -- _OTMoveIt
16/02/2008 20:16:19 704643072 byte 0 days old -- pagefile.sys
16/02/2008 20:22:48 (DIR) 0 byte 0 days old -- WINDOWS
16/02/2008 21:56:01 (DIR) 0 byte 0 days old -- Downloads
16/02/2008 21:58:17 (DIR) 0 byte 0 days old -- suspectfile
----- recent files in C:\WINDOWS\
18/01/2008 16:11:36 (DIR) 0 byte 29 days old -- network diagnostic
18/01/2008 19:14:36 115200 byte 29 days old -- snap.dat
19/01/2008 19:44:05 151 byte 28 days old -- PhotoSnapViewer.INI
08/02/2008 14:40:23 691545 byte 8 days old -- unins000.exe
08/02/2008 14:40:58 3456 byte 8 days old -- unins000.dat
12/02/2008 16:26:04 (DIR) 0 byte 4 days old -- Minidump
13/02/2008 12:02:31 (DIR) 0 byte 3 days old -- $hf_mig$
13/02/2008 15:03:26 (DIR) 0 byte 3 days old -- ie7updates
13/02/2008 19:05:54 (DIR) 0 byte 3 days old -- inf
13/02/2008 19:33:24 (DIR) 0 byte 3 days old -- WinSxS
13/02/2008 19:53:30 (DIR) 0 byte 3 days old -- assembly
13/02/2008 19:53:50 (DIR) 0 byte 3 days old -- Microsoft.NET
15/02/2008 16:16:16 (DIR) 0 byte 1 days old -- Installer
15/02/2008 16:24:01 (DIR) 0 byte 1 days old -- pss
15/02/2008 16:24:44 562 byte 1 days old -- win.ini
15/02/2008 16:24:44 227 byte 1 days old -- system.ini
16/02/2008 14:38:28 116 byte 0 days old -- NeroDigital.ini
16/02/2008 15:30:07 (DIR) 0 byte 0 days old -- Debug
16/02/2008 15:34:21 (DIR) 0 byte 0 days old -- Downloaded Program Files
16/02/2008 17:36:56 32522 byte 0 days old -- SchedLgU.Txt
16/02/2008 17:38:58 234292 byte 0 days old -- ntbtlog.txt
16/02/2008 19:06:58 8207 byte 0 days old -- setupapi.log
16/02/2008 19:53:03 (DIR) 0 byte 0 days old -- system32
16/02/2008 20:16:22 2048 byte 0 days old -- bootstat.dat
16/02/2008 20:17:08 50 byte 0 days old -- wiaservc.log
16/02/2008 20:17:11 159 byte 0 days old -- wiadebug.log
16/02/2008 20:17:13 1391494 byte 0 days old -- WindowsUpdate.log
16/02/2008 20:17:30 0 byte 0 days old -- 0.log
16/02/2008 20:43:29 (DIR) 0 byte 0 days old -- Temp
16/02/2008 21:54:55 (DIR) 0 byte 0 days old -- Internet Logs
16/02/2008 21:58:15 (DIR) 0 byte 0 days old -- Prefetch
----- recent files in C:\WINDOWS\Downloaded Program Files\
----- recent files in C:\WINDOWS\system\
----- recent files in C:\WINDOWS\system32\
26/01/2008 10:46:15 (DIR) 0 byte 21 days old -- Macromed
29/01/2008 15:08:40 (DIR) 0 byte 18 days old -- CatRoot
05/02/2008 00:09:46 18214008 byte 11 days old -- MRT.exe
13/02/2008 15:04:47 (DIR) 0 byte 3 days old -- dllcache
13/02/2008 19:34:15 77278 byte 3 days old -- perfc00C.dat
13/02/2008 19:34:15 988696 byte 3 days old -- PerfStringBackup.INI
13/02/2008 19:34:15 474734 byte 3 days old -- perfh00C.dat
13/02/2008 19:34:15 406464 byte 3 days old -- perfh009.dat
13/02/2008 19:34:15 63664 byte 3 days old -- perfc009.dat
15/02/2008 13:36:08 4212 byte 1 days old -- zllictbl.dat
15/02/2008 18:41:57 (DIR) 0 byte 1 days old -- ZoneLabs
16/02/2008 16:34:08 (DIR) 0 byte 0 days old -- CatRoot2
16/02/2008 16:50:03 (DIR) 0 byte 0 days old -- bfubackups
16/02/2008 19:06:58 (DIR) 0 byte 0 days old -- drivers
16/02/2008 20:18:16 358830 byte 0 days old -- vsconfig.xml
16/02/2008 20:19:50 13646 byte 0 days old -- wpa.dbl
----- recent files in C:\WINDOWS\system32\drivers\
08/02/2008 15:13:52 (DIR) 0 byte 8 days old -- etc
16/02/2008 20:15:38 58328 byte 0 days old -- fidbox.idx
16/02/2008 21:58:06 4316960 byte 0 days old -- fidbox.dat
----- recent files in C:\WINDOWS\temp\
16/02/2008 17:52:41 256 byte 0 days old -- ZLT00916.TMP
16/02/2008 17:52:41 256 byte 0 days old -- ZLT04aab.TMP
16/02/2008 17:53:10 16384 byte 0 days old -- Perflib_Perfdata_708.dat
16/02/2008 18:13:06 256 byte 0 days old -- ZLT018b3.TMP
16/02/2008 18:13:06 256 byte 0 days old -- ZLT018b6.TMP
16/02/2008 19:06:26 256 byte 0 days old -- ZLT04188.TMP
16/02/2008 19:06:26 256 byte 0 days old -- ZLT0068d.TMP
16/02/2008 19:06:36 16384 byte 0 days old -- Perflib_Perfdata_714.dat
16/02/2008 19:53:11 256 byte 0 days old -- ZLT06550.TMP
16/02/2008 19:53:11 256 byte 0 days old -- ZLT0654c.TMP
16/02/2008 19:53:22 16384 byte 0 days old -- Perflib_Perfdata_704.dat
16/02/2008 20:16:24 255 byte 0 days old -- WGAErrLog.txt
16/02/2008 20:16:26 256 byte 0 days old -- ZLT0771b.TMP
16/02/2008 20:16:26 256 byte 0 days old -- ZLT05b98.TMP
16/02/2008 20:16:54 16384 byte 0 days old -- Perflib_Perfdata_750.dat
16/02/2008 20:20:47 409 byte 0 days old -- WGANotify.settings
16/02/2008 21:58:25 (DIR) 0 byte 0 days old -- _avast4_
----- recent files in C:\Program Files\
29/01/2008 17:20:05 (DIR) 0 byte 18 days old -- Cyanide
30/01/2008 22:11:05 (DIR) 0 byte 17 days old -- StreamerOne
02/02/2008 13:40:48 (DIR) 0 byte 14 days old -- GF38_Immersive_Stadium
08/02/2008 14:46:05 (DIR) 0 byte 8 days old -- Spybot - Search & Destroy
10/02/2008 21:11:12 (DIR) 0 byte 6 days old -- TVAnts
12/02/2008 17:40:19 (DIR) 0 byte 4 days old -- a-squared Free
12/02/2008 19:07:07 (DIR) 0 byte 4 days old -- Zone Labs
13/02/2008 15:03:51 (DIR) 0 byte 3 days old -- Internet Explorer
14/02/2008 14:50:46 (DIR) 0 byte 2 days old -- Spyware Doctor
15/02/2008 15:54:30 (DIR) 0 byte 1 days old -- Trend Micro
15/02/2008 16:18:44 (DIR) 0 byte 1 days old -- Gamenext
15/02/2008 18:07:55 (DIR) 0 byte 1 days old -- eMule
16/02/2008 15:18:01 (DIR) 0 byte 0 days old -- Navilog1
16/02/2008 18:33:56 (DIR) 0 byte 0 days old -- a-squared Anti-Malware
----- recent files in C:\Program Files\Fichiers communs\
16/02/2008 18:33:07 (DIR) 0 byte 0 days old -- Adobe
----- recent files in C:\Documents and Settings\Ordi\Application Data\
23/01/2008 21:39:40 (DIR) 0 byte 24 days old -- TVU Networks
25/01/2008 12:44:47 (DIR) 0 byte 22 days old -- Adobe
12/02/2008 19:24:52 (DIR) 0 byte 4 days old -- MailFrontier
15/02/2008 16:16:16 (DIR) 0 byte 1 days old -- Microsoft
16/02/2008 17:41:02 (DIR) 0 byte 0 days old -- OpenOffice.org2
----- recent files in C:\DOCUME~1\Ordi\LOCALS~1\Temp\
16/02/2008 17:57:42 1342 byte 0 days old -- MAR11.tmp
16/02/2008 17:57:49 1285 byte 0 days old -- MAR12.tmp
16/02/2008 17:58:18 16384 byte 0 days old -- ~DF4997.tmp
16/02/2008 17:59:16 114688 byte 0 days old -- ~DF8D15.tmp
16/02/2008 17:59:17 512 byte 0 days old -- ~DFAAB8.tmp
16/02/2008 18:00:04 16384 byte 0 days old -- ~DFEC39.tmp
16/02/2008 18:00:05 114688 byte 0 days old -- ~DFF193.tmp
16/02/2008 18:00:05 512 byte 0 days old -- ~DFF3CF.tmp
16/02/2008 18:01:19 109 byte 0 days old -- STS14.tmp
16/02/2008 18:10:25 (DIR) 0 byte 0 days old -- Google Toolbar
16/02/2008 18:20:19 16384 byte 0 days old -- ~DFEF68.tmp
16/02/2008 18:20:22 1342 byte 0 days old -- MAR1.tmp
16/02/2008 18:20:26 1285 byte 0 days old -- MAR2.tmp
16/02/2008 18:21:15 16384 byte 0 days old -- ~DF7B6.tmp
16/02/2008 18:21:45 109 byte 0 days old -- STS4.tmp
16/02/2008 18:34:56 (DIR) 0 byte 0 days old -- {4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
16/02/2008 19:06:17 (DIR) 0 byte 0 days old -- ~nsu.tmp
16/02/2008 19:09:50 16384 byte 0 days old -- ~DF7FAF.tmp
16/02/2008 19:59:41 1342 byte 0 days old -- MAR3.tmp
16/02/2008 19:59:43 16384 byte 0 days old -- ~DF5930.tmp
16/02/2008 19:59:49 1285 byte 0 days old -- MAR4.tmp
16/02/2008 20:02:14 109 byte 0 days old -- STS6.tmp
16/02/2008 20:10:36 (DIR) 0 byte 0 days old -- bc_tmp
16/02/2008 20:10:48 (DIR) 0 byte 0 days old -- bc_cache
16/02/2008 20:14:36 8979 byte 0 days old -- hpodvd09.log
16/02/2008 20:19:19 (DIR) 0 byte 0 days old -- WPDNSE
16/02/2008 20:22:33 1342 byte 0 days old -- MAR14.tmp
16/02/2008 20:22:36 1285 byte 0 days old -- MAR15.tmp
16/02/2008 20:22:48 16384 byte 0 days old -- ~DFB504.tmp
16/02/2008 20:23:44 114688 byte 0 days old -- ~DFBF1.tmp
16/02/2008 20:23:44 512 byte 0 days old -- ~DFD5C.tmp
16/02/2008 20:23:51 16384 byte 0 days old -- ~DFD376.tmp
16/02/2008 20:24:02 512 byte 0 days old -- ~DF1DC1.tmp
16/02/2008 20:24:02 114688 byte 0 days old -- ~DF1C92.tmp
16/02/2008 20:24:03 109 byte 0 days old -- STS17.tmp
16/02/2008 20:29:21 (DIR) 0 byte 0 days old -- MessengerCache
16/02/2008 20:29:34 1020 byte 0 days old -- jusched.log
16/02/2008 20:56:21 835584 byte 0 days old -- ~DF78D9.tmp
16/02/2008 21:31:09 (DIR) 0 byte 0 days old -- F-Secure
16/02/2008 21:55:50 (DIR) 0 byte 0 days old -- _avast4_
16/02/2008 21:57:13 25 byte 0 days old -- systemscan.ini
16/02/2008 21:57:22 16384 byte 0 days old -- ~DF6677.tmp
16/02/2008 21:57:22 16384 byte 0 days old -- ~DF6689.tmp
16/02/2008 21:57:25 (DIR) 0 byte 0 days old -- nsf27.tmp
16/02/2008 21:57:25 (DIR) 0 byte 0 days old -- nsa28.tmp
==========================================
Scan completed in 0,4 minutes
End of report
~~~~~~~~~~~~~~~~~~~~~-----CREDITS-----~~~~~~~~~~~~~~~~~~~~~
SystemScan uses some freeware tools that remain property of their authors:
* SteelWerX Registry Console Tool, Who Am I (Bobby Flekman: www.xs4all.nl/~fstaal01) --> "Registry scan", "PC accounts "
* dumphive (Markus Stephany)--> "Registry scan"
* Listdlls (M.Russinovich, B.Cogswell: www.sysinternals.com) --> "Loaded modules"
* Catchme & MBR Rootkit detector (gmer: www.gmer.net) --> "Hidden objects", "Alternate Data Streams" & "Master Boot Record"
---> NOTE: SystemScan integrates "The Avenger" from Swandog46 (http://swandog46.geekstogo.com) to allow you to remove malwares found in this log
Thanks to all of them for their hard work
lance hijack this pour un scan et coche les lignes suivantes
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [susqhjcqr] c:\documents and settings\ordi\local settings\application data\susqhjcqr.exe susqhjcqr
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
ferme toutes tes fenêtres et clique sur fix checked
Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires.
Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires".
Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Par la suite, laisse-le avec ses réglages par défaut. C'est tout
Lance CCleaner , nettoyeur, et supprime tout ce qu'il trouve
lance CCleaner erreur et répare ce qu'il trouve, accepte les sauvegardes
Télécharge clean.zip, de Malekal
http://www.malekal.com/download/clean.zip
décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.
Choisis l'option 1 puis patiente
Poste le rapport obtenu
S’il te demande d’uploader un fichier, tu le fais…
s'il trouve quelque chose
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur
Ouvre le dossier jaune nommé clean sur ton bureau.
Double-clique sur clean.cmd
Choisis l'option 2 et copie sur le bureau le rapport généré.
Si une fenêtre s'ouvre, laisse-la.
Clique sur Q pour quitter le programme.
redémarre normalement et poste moi les rapports obtenus
faire un scan antivirus en ligne avec Internet explorer et accepter l'ActiveX
poster le rapport ici ensuite
https://www.bitdefender.fr/
En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
Dans la nouvelle fenêtre, clique sur j’accepte
La fenêtre change encore, clique sur scanner
Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
à demain pour la suite et fin j'espère
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [susqhjcqr] c:\documents and settings\ordi\local settings\application data\susqhjcqr.exe susqhjcqr
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
ferme toutes tes fenêtres et clique sur fix checked
Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires.
Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires".
Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Par la suite, laisse-le avec ses réglages par défaut. C'est tout
Lance CCleaner , nettoyeur, et supprime tout ce qu'il trouve
lance CCleaner erreur et répare ce qu'il trouve, accepte les sauvegardes
Télécharge clean.zip, de Malekal
http://www.malekal.com/download/clean.zip
décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.
Choisis l'option 1 puis patiente
Poste le rapport obtenu
S’il te demande d’uploader un fichier, tu le fais…
s'il trouve quelque chose
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur
Ouvre le dossier jaune nommé clean sur ton bureau.
Double-clique sur clean.cmd
Choisis l'option 2 et copie sur le bureau le rapport généré.
Si une fenêtre s'ouvre, laisse-la.
Clique sur Q pour quitter le programme.
redémarre normalement et poste moi les rapports obtenus
faire un scan antivirus en ligne avec Internet explorer et accepter l'ActiveX
poster le rapport ici ensuite
https://www.bitdefender.fr/
En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
Dans la nouvelle fenêtre, clique sur j’accepte
La fenêtre change encore, clique sur scanner
Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
à demain pour la suite et fin j'espère
Salut pour pas changer il y a un petit probleme.
Lorsque je doit envoyer le fichier upload_moi on me dit que le fichier est invalide...
Lorsque je doit envoyer le fichier upload_moi on me dit que le fichier est invalide...
Il y a 2 rapports je sais pas pourquoi :
le 1er:
C:\WINDOWS\System32\wpa.dbl -->17/02/2008 16:37:15
C:\WINDOWS\System32\vsconfig.xml -->17/02/2008 16:36:18
C:\WINDOWS\System32\zllictbl.dat -->15/02/2008 13:36:08
C:\WINDOWS\System32\PerfStringBackup.INI -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfh00C.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfh009.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfc00C.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfc009.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\MRT.exe -->05/02/2008 00:09:46
C:\WINDOWS\System32\CONFIG.NT -->14/01/2008 12:18:13
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\dxtmsft.dll -->19/12/2007 23:53:23
C:\WINDOWS\System32\vsutil_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\System32\imslsp_install_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\imsinstall_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\vsdatant.sys -->13/12/2007 19:27:14
C:\WINDOWS\System32\zpeng24.dll -->13/12/2007 19:27:04
C:\WINDOWS\System32\zlcommdb.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\zlcomm.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsxml.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vswmi.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsutil.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsregexp.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vspubapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vsmonapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\0.log -->17/02/2008 16:35:22
C:\WINDOWS\wiadebug.log -->17/02/2008 16:34:28
C:\WINDOWS\wiaservc.log -->17/02/2008 16:34:25
C:\WINDOWS\bootstat.dat -->17/02/2008 16:33:28
C:\WINDOWS\SchedLgU.Txt -->16/02/2008 23:04:38
C:\WINDOWS\WindowsUpdate.log -->16/02/2008 23:03:30
C:\WINDOWS\NeroDigital.ini -->16/02/2008 14:38:28
C:\WINDOWS\win.ini -->15/02/2008 16:24:44
C:\WINDOWS\system.ini -->15/02/2008 16:24:44
C:\WINDOWS\unins000.dat -->08/02/2008 14:40:58
C:\WINDOWS\unins000.exe -->08/02/2008 14:40:23
C:\WINDOWS\PhotoSnapViewer.INI -->19/01/2008 19:44:05
C:\WINDOWS\snap.dat -->18/01/2008 19:14:36
C:\WINDOWS\zllsputility_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\zllsputility.exe -->13/12/2007 19:27:10
le 2eme:
C:\WINDOWS\System32\MRT.exe -->05/02/2008 00:09:46
C:\WINDOWS\unins000.exe -->08/02/2008 14:40:23
C:\WINDOWS\zllsputility.exe -->13/12/2007 19:27:10
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\dxtmsft.dll -->19/12/2007 23:53:23
C:\WINDOWS\System32\vsutil_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\System32\imslsp_install_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\imsinstall_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\zpeng24.dll -->13/12/2007 19:27:04
C:\WINDOWS\System32\zlcommdb.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\zlcomm.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsxml.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vswmi.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsutil.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsregexp.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vspubapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vsmonapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\zllsputility_loc040c.dll -->13/12/2007 19:27:48
le 1er:
C:\WINDOWS\System32\wpa.dbl -->17/02/2008 16:37:15
C:\WINDOWS\System32\vsconfig.xml -->17/02/2008 16:36:18
C:\WINDOWS\System32\zllictbl.dat -->15/02/2008 13:36:08
C:\WINDOWS\System32\PerfStringBackup.INI -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfh00C.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfh009.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfc00C.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\perfc009.dat -->13/02/2008 19:34:15
C:\WINDOWS\System32\MRT.exe -->05/02/2008 00:09:46
C:\WINDOWS\System32\CONFIG.NT -->14/01/2008 12:18:13
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\dxtmsft.dll -->19/12/2007 23:53:23
C:\WINDOWS\System32\vsutil_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\System32\imslsp_install_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\imsinstall_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\vsdatant.sys -->13/12/2007 19:27:14
C:\WINDOWS\System32\zpeng24.dll -->13/12/2007 19:27:04
C:\WINDOWS\System32\zlcommdb.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\zlcomm.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsxml.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vswmi.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsutil.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsregexp.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vspubapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vsmonapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\0.log -->17/02/2008 16:35:22
C:\WINDOWS\wiadebug.log -->17/02/2008 16:34:28
C:\WINDOWS\wiaservc.log -->17/02/2008 16:34:25
C:\WINDOWS\bootstat.dat -->17/02/2008 16:33:28
C:\WINDOWS\SchedLgU.Txt -->16/02/2008 23:04:38
C:\WINDOWS\WindowsUpdate.log -->16/02/2008 23:03:30
C:\WINDOWS\NeroDigital.ini -->16/02/2008 14:38:28
C:\WINDOWS\win.ini -->15/02/2008 16:24:44
C:\WINDOWS\system.ini -->15/02/2008 16:24:44
C:\WINDOWS\unins000.dat -->08/02/2008 14:40:58
C:\WINDOWS\unins000.exe -->08/02/2008 14:40:23
C:\WINDOWS\PhotoSnapViewer.INI -->19/01/2008 19:44:05
C:\WINDOWS\snap.dat -->18/01/2008 19:14:36
C:\WINDOWS\zllsputility_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\zllsputility.exe -->13/12/2007 19:27:10
le 2eme:
C:\WINDOWS\System32\MRT.exe -->05/02/2008 00:09:46
C:\WINDOWS\unins000.exe -->08/02/2008 14:40:23
C:\WINDOWS\zllsputility.exe -->13/12/2007 19:27:10
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\dxtmsft.dll -->19/12/2007 23:53:23
C:\WINDOWS\System32\vsutil_loc040c.dll -->13/12/2007 19:27:48
C:\WINDOWS\System32\imslsp_install_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\imsinstall_loc040c.dll -->13/12/2007 19:27:44
C:\WINDOWS\System32\zpeng24.dll -->13/12/2007 19:27:04
C:\WINDOWS\System32\zlcommdb.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\zlcomm.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsxml.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vswmi.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsutil.dll -->13/12/2007 19:26:58
C:\WINDOWS\System32\vsregexp.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vspubapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\System32\vsmonapi.dll -->13/12/2007 19:26:56
C:\WINDOWS\zllsputility_loc040c.dll -->13/12/2007 19:27:48
C'est bon j'ai trouvé
17/02/2008 a 16:52:06,17
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\mcrh.tmp FOUND
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\Adverts\" FOUND
"C:\Program Files\Multi_Media_France\" FOUND
17/02/2008 a 16:52:06,17
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\mcrh.tmp FOUND
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\Adverts\" FOUND
"C:\Program Files\Multi_Media_France\" FOUND
Redémarre en mode sans échec
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur
Ouvre le dossier jaune nommé clean sur ton bureau.
Double-clique sur clean.cmd
Choisis l'option 2 et copie sur le bureau le rapport généré.
Si une fenêtre s'ouvre, laisse-la.
Clique sur Q pour quitter le programme.
redémarre normalement et poste moi les rapports obtenus
ton PC rame toujours?
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur
Ouvre le dossier jaune nommé clean sur ton bureau.
Double-clique sur clean.cmd
Choisis l'option 2 et copie sur le bureau le rapport généré.
Si une fenêtre s'ouvre, laisse-la.
Clique sur Q pour quitter le programme.
redémarre normalement et poste moi les rapports obtenus
ton PC rame toujours?
Voila le rapport
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 17/02/2008 a 17:27:41,93
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\mcrh.tmp
tentative de suppression de "C:\WINDOWS\Downloaded Program Files\CONFLICT.1"
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\Adverts\"
tentative de suppression de "C:\Program Files\Multi_Media_France\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 17/02/2008 a 17:27:41,93
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\mcrh.tmp
tentative de suppression de "C:\WINDOWS\Downloaded Program Files\CONFLICT.1"
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\Adverts\"
tentative de suppression de "C:\Program Files\Multi_Media_France\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:56:22, on 17/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra 'Tools' menuitem: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://regulus.upmf-grenoble.fr/qp2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Scan saved at 17:56:22, on 17/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Multi_Media_France toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra 'Tools' menuitem: Stop Pub - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\JCA2000\StopPub\StopPub.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://regulus.upmf-grenoble.fr/qp2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe