Pub cid tout le temp
Résolu
Utilisateur anonyme
-
snoopy08 -
snoopy08 -
Bonjour, pouvez vous m'aider j'ai des tas de pub cid qui arrive sur mon pc impossible de les enlevées malgré fenetre popoup bloquées dans internet explorer avast com anti virus spywar doctor com anti spam fenetres publicitaires bloquées partout mai elles reviennent quand meme que faire? au secour ...............................
A voir également:
- Pub cid tout le temp
- Supprimer pub youtube - Accueil - Streaming
- Stop pub gratuit - Télécharger - Divers Utilitaires
- Core temp - Télécharger - Divers Utilitaires
- Supprimer la pub - Guide
- Pourquoi mon compte google se deconnecte tout le temps ? ✓ - Forum Google Chrome
102 réponses
Il n'est pas complet.
Ne met pas tes messages en réponses mais en nouveau message sinon la file est impossible à suivre chronologiquement.
DllD te l'as demandé.
Ne met pas tes messages en réponses mais en nouveau message sinon la file est impossible à suivre chronologiquement.
DllD te l'as demandé.
ok piger maintenant mai quand je reclic sur anti vir tout est en anglais ou il fo que j'aille pour refaire une analyse?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
AntiVir PersonalEdition Classic
Report file date: dimanche 16 mars 2008 21:47
Scanning for 835736 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: jim
Computer name: JIM-AE4D62D1214
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:13
AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 16 mars 2008 21:47
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '0' Module(s) have been scanned
Scan process 'antivir_workstation_win7u_en_h[1].exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'fsus.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'fsaua.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'pctsTray.exe' - '1' Module(s) have been scanned
Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
Scan process 'fspc.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'FAMEH32.EXE' - '1' Module(s) have been scanned
Scan process 'FCH32.EXE' - '1' Module(s) have been scanned
Scan process 'FSMB32.EXE' - '1' Module(s) have been scanned
Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
Scan process 'FSMA32.EXE' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '20' files ).
Starting the file scan:
Begin scan in 'C:\WINDOWS\system32'
End of the scan: dimanche 16 mars 2008 21:52
Used time: 05:20 min
The scan has been done completely.
160 Scanning directories
6462 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
6462 Files not concerned
5 Archives were scanned
0 Warnings
0 Notes
voila j'avais du rater un bout mais sa viendra je persevere
Report file date: dimanche 16 mars 2008 21:47
Scanning for 835736 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: jim
Computer name: JIM-AE4D62D1214
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
ANTIVIR2.VDF : 7.0.0.1 2048 Bytes 13/09/2007 14:27:04
ANTIVIR3.VDF : 7.0.0.2 2048 Bytes 13/09/2007 14:27:13
AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 17/09/2007 17:43:56
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setupprf.dat
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 16 mars 2008 21:47
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '0' Module(s) have been scanned
Scan process 'antivir_workstation_win7u_en_h[1].exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'fsus.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'fsaua.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'pctsTray.exe' - '1' Module(s) have been scanned
Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
Scan process 'fspc.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'FAMEH32.EXE' - '1' Module(s) have been scanned
Scan process 'FCH32.EXE' - '1' Module(s) have been scanned
Scan process 'FSMB32.EXE' - '1' Module(s) have been scanned
Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
Scan process 'FSMA32.EXE' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
35 processes with 35 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '20' files ).
Starting the file scan:
Begin scan in 'C:\WINDOWS\system32'
End of the scan: dimanche 16 mars 2008 21:52
Used time: 05:20 min
The scan has been done completely.
160 Scanning directories
6462 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
6462 Files not concerned
5 Archives were scanned
0 Warnings
0 Notes
voila j'avais du rater un bout mais sa viendra je persevere
oui apparement ya des trucs commes des cookies et autre une menace elevée d'autre moyennes et basse
Mmmm
Comment ça ? avec AVG ? De toute façon supprime tout ce qu'il trouve.
Poste les rapports stp.
En fait suis les consignes que ce trouvent ici : http://www.commentcamarche.net/forum/affich 5465599 pub cid tout le temp?page=2#68
Et puis on verra ensuite.
A+
:)
Comment ça ? avec AVG ? De toute façon supprime tout ce qu'il trouve.
Poste les rapports stp.
En fait suis les consignes que ce trouvent ici : http://www.commentcamarche.net/forum/affich 5465599 pub cid tout le temp?page=2#68
Et puis on verra ensuite.
A+
:)
Re,
voila j'avais du rater un bout mais sa viendra je persevere,
:))))
Passe à la suite l'artiste !
;)
voila j'avais du rater un bout mais sa viendra je persevere,
:))))
Passe à la suite l'artiste !
;)
quand j'ouvre sdfix sur le bureau ya des trucs dedans et quand je clic dessu soit j'ai des fenetres noires soit sa me dirige vers une adresse inter net avec plin de trucs en anglais
pourkoi n'est je pas pris anglais comme langue a l'ecole ???
pourkoi n'est je pas pris anglais comme langue a l'ecole ???
Mmmm...
Doly il va falloir faire un effort !!!
:)))))
Si tu suis les consignes qui se trouvent ici : http://www.commentcamarche.net/forum/affich 5465599 pub cid tout le temp?page=2#68
Tu t'apercevra que tu dois :
1°/ Installer les programmes, faire les mises à jour puis les fermer sans avoir executer les scannes.
2°/ Démarrer en mode sans échec.
3°/ Lance les scannes en modes sans Echec.
A+
Oufff !!!!
:)
Doly il va falloir faire un effort !!!
:)))))
Si tu suis les consignes qui se trouvent ici : http://www.commentcamarche.net/forum/affich 5465599 pub cid tout le temp?page=2#68
Tu t'apercevra que tu dois :
1°/ Installer les programmes, faire les mises à jour puis les fermer sans avoir executer les scannes.
2°/ Démarrer en mode sans échec.
3°/ Lance les scannes en modes sans Echec.
A+
Oufff !!!!
:)
bon je finirais demain et je posterais tout demain merci a demain ( les pauvres suis pas une mince affaire ) mai bon fo un debut a tout dis -t-on .
Logfile of HijackThis v1.99.1
Scan saved at 02:15:46, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\RaUI.exe
C:\Documents and Settings\selim\Bureau\anti.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\selim\Bureau\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\selim\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Raccourci vers anti.lnk = C:\Documents and Settings\selim\Bureau\anti.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\WINDOWS\RaUI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
Scan saved at 02:15:46, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\RaUI.exe
C:\Documents and Settings\selim\Bureau\anti.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\selim\Bureau\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\selim\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Raccourci vers anti.lnk = C:\Documents and Settings\selim\Bureau\anti.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\WINDOWS\RaUI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
Logfile of HijackThis v1.99.1
Scan saved at 02:15:46, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\RaUI.exe
C:\Documents and Settings\selim\Bureau\anti.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\selim\Bureau\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\selim\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Raccourci vers anti.lnk = C:\Documents and Settings\selim\Bureau\anti.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\WINDOWS\RaUI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
Scan saved at 02:15:46, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\RaUI.exe
C:\Documents and Settings\selim\Bureau\anti.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\selim\Bureau\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\selim\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Raccourci vers anti.lnk = C:\Documents and Settings\selim\Bureau\anti.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\WINDOWS\RaUI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
bonjours a vous deux : donc voila le---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 10:35:57 17/03/2008
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B8705110-D7BE-41E8-B4C6-F47AFE990462}\RP141\A0159902.exe -> Not-A-Virus.Hacktool.EvID : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@overture[1].txt -> TrackingCookie.Overture : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@argenius.solution.weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
Fin du rapport
s rapports : avg , cclean, clean , ( hijackthis mode normal )
[b]SDFix: Version 1.158 /b
Run by jim on 17/03/2008 at 11:30
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\jim\Bureau\SDFix
[b]Checking Services /b:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 11:41:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eChanblard"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
"C:\\Documents and Settings\\jim\\Local Settings\\Temp\\Rar$EX01.377\\emule\\eMule.exe"="C:\\Documents and Settings\\jim\\Local Settings\\Temp\\Rar$EX01.377\\emule\\eMule.exe:*:Disabled:eMule"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[b]Remaining Files /b:
File Backups: - C:\DOCUME~1\jim\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Fri 14 Mar 2008 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sun 4 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 5 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 14 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT18.tmp"
[b]Finished!/b
AntiVir PersonalEdition Classic
Report file date: lundi 17 mars 2008 10:39
Scanning for 1149639 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: jim
Computer name: JIM-AE4D62D1214
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 07:47:04
ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 07:47:04
ANTIVIR3.VDF : 7.0.3.34 182784 Bytes 17/03/2008 07:47:04
AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 17/03/2008 07:47:05
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 17/03/2008 07:47:06
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 17 mars 2008 10:39
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
16 processes with 16 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '20' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\afocef.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d44a2.qua'!
C:\WINDOWS\system32\aldxvbbccb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484244ac.qua'!
C:\WINDOWS\system32\atzjktd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485844b9.qua'!
C:\WINDOWS\system32\avjimca.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844bd.qua'!
C:\WINDOWS\system32\bdujibxue.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485344ac.qua'!
C:\WINDOWS\system32\bwljrnmh.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484a44c1.qua'!
C:\WINDOWS\system32\cltufbjcp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244bb.qua'!
C:\WINDOWS\system32\cmboojrkdq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484044bd.qua'!
C:\WINDOWS\system32\cpvhmaalyp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485444c4.qua'!
C:\WINDOWS\system32\creaylauj.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484344c7.qua'!
C:\WINDOWS\system32\cvqizomwy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44cd.qua'!
C:\WINDOWS\system32\dxecyr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484344df.qua'!
C:\WINDOWS\system32\dxhtuox.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484644df.qua'!
C:\WINDOWS\system32\dyjgngopk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844e1.qua'!
C:\WINDOWS\system32\eprxjyi.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485044da.qua'!
C:\WINDOWS\system32\eyrdejsrqa.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485044e5.qua'!
C:\WINDOWS\system32\fhqnnss.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44d5.qua'!
C:\WINDOWS\system32\fmffczb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444dc.qua'!
C:\WINDOWS\system32\fohbajy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484644de.qua'!
C:\WINDOWS\system32\ftkyznvw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484944e5.qua'!
C:\WINDOWS\system32\gkhkzub.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '493af6f7.qua'!
C:\WINDOWS\system32\gtmkyik.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b44e8.qua'!
C:\WINDOWS\system32\gwtyzunlt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244ec.qua'!
C:\WINDOWS\system32\hwotjzt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d44ee.qua'!
C:\WINDOWS\system32\hxsqmrbgl.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485144f0.qua'!
C:\WINDOWS\system32\iokdiyykd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484944ee.qua'!
C:\WINDOWS\system32\iqfaoqm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444f3.qua'!
C:\WINDOWS\system32\irssbbykz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485144f6.qua'!
C:\WINDOWS\system32\iuxxbos.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485644fa.qua'!
C:\WINDOWS\system32\jbjujwzdzk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844e9.qua'!
C:\WINDOWS\system32\jeaifmmijs.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f44ec.qua'!
C:\WINDOWS\system32\jgnvejci.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484c44ef.qua'!
C:\WINDOWS\system32\jiqroklaa.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44f2.qua'!
C:\WINDOWS\system32\jltazv.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244f6.qua'!
C:\WINDOWS\system32\jpayieuvo.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f44fb.qua'!
C:\WINDOWS\system32\jqfmcuz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444fc.qua'!
C:\WINDOWS\system32\jypyhir.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e4505.qua'!
C:\WINDOWS\system32\jzbjtio.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48404507.qua'!
C:\WINDOWS\system32\kprlhqqva.exe
[DETECTION] Is the Trojan horse TR/Agent.306688
[INFO] The file was moved to '48504501.qua'!
C:\WINDOWS\system32\lbpzcdobjw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e44f5.qua'!
C:\WINDOWS\system32\ldnuciil.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484c44f7.qua'!
C:\WINDOWS\system32\lezludsqgz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485844f9.qua'!
C:\WINDOWS\system32\ljohtjvjd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d4504.qua'!
C:\WINDOWS\system32\llhogfgugh.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48464507.qua'!
C:\WINDOWS\system32\lprcwfd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4850450d.qua'!
C:\WINDOWS\system32\nbuujob.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4853451a.qua'!
C:\WINDOWS\system32\nftiig.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524522.qua'!
C:\WINDOWS\system32\ngrdhp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48504524.qua'!
C:\WINDOWS\system32\nktuznz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524529.qua'!
C:\WINDOWS\system32\npxugofyt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4856452f.qua'!
C:\WINDOWS\system32\nybobqtx.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4840453c.qua'!
C:\WINDOWS\system32\pgtswy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524532.qua'!
C:\WINDOWS\system32\psqxgovyo.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f4541.qua'!
C:\WINDOWS\system32\pvfqqqi.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48444545.qua'!
C:\WINDOWS\system32\qayajlphez.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574532.qua'!
C:\WINDOWS\system32\qjjblpx.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4848453c.qua'!
C:\WINDOWS\system32\qjmauvuxd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b453d.qua'!
C:\WINDOWS\system32\qvlpjnlfp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484a454a.qua'!
C:\WINDOWS\system32\recrszgj.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4841453d.qua'!
C:\WINDOWS\system32\rvyqknn.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574552.qua'!
C:\WINDOWS\system32\sftodny.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524549.qua'!
C:\WINDOWS\system32\slbolsg.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48404552.qua'!
C:\WINDOWS\system32\sodqsy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48424556.qua'!
C:\WINDOWS\system32\syajej.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f456d.qua'!
C:\WINDOWS\system32\tfdsvblal.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4842455e.qua'!
C:\WINDOWS\system32\ugarougm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f4565.qua'!
C:\WINDOWS\system32\ukhfgikwu.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4846456a.qua'!
C:\WINDOWS\system32\vdhhzcjrri.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '493af743.qua'!
C:\WINDOWS\system32\vixmfkzxxz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48564570.qua'!
C:\WINDOWS\system32\vqqlwm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f457b.qua'!
C:\WINDOWS\system32\vuoijvw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d4580.qua'!
C:\WINDOWS\system32\vweajw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48434583.qua'!
C:\WINDOWS\system32\wipsnyp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e457b.qua'!
C:\WINDOWS\system32\wjebsmb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4843457d.qua'!
C:\WINDOWS\system32\xmxjkq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4856458d.qua'!
C:\WINDOWS\system32\xnwapnxgr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4855458f.qua'!
C:\WINDOWS\system32\xoiuxcab.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48474591.qua'!
C:\WINDOWS\system32\yocsxrc.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48414593.qua'!
C:\WINDOWS\system32\ypkqogej.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48494595.qua'!
C:\WINDOWS\system32\yryawxomf.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574598.qua'!
C:\WINDOWS\system32\ywmruatyq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b459e.qua'!
C:\WINDOWS\system32\zbjjev.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48484589.qua'!
C:\WINDOWS\system32\zdzwjbu.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4858458c.qua'!
C:\WINDOWS\system32\zfsnhbr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4851458e.qua'!
C:\WINDOWS\system32\zgyizwny.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574590.qua'!
C:\WINDOWS\system32\zxvads.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485445a2.qua'!
C:\WINDOWS\system32\zytindzk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485245a4.qua'!
End of the scan: lundi 17 mars 2008 11:21
Used time: 42:19 min
The scan has been done completely.
2884 Scanning directories
93785 Files were scanned
87 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
87 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
93698 Files not concerned
714 Archives were scanned
1 Warnings
0 Notes
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\COVEREDCTRL.CoverEdCtrl.1]
@="CoverEdCtrl Control"
[HKEY_CLASSES_ROOT\COVEREDCTRL.CoverEdCtrl.1\CLSID]
@="{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin\CLSID]
@="{896E73F0-3851-11D3-AA54-00C04FD22F8C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin\CurVer]
@="MDNeroBurnPlugin.MDNeroBurnPlugin.1"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin.1]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin.1\CLSID]
@="{896E73F0-3851-11D3-AA54-00C04FD22F8C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage]
@="HDSPPropPage Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage\CLSID]
@="{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage\CurVer]
@="MDNeroBurnPlugin.PropPage.1"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage.1]
@="PropPage Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage.1\CLSID]
@="{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}"
[HKEY_CLASSES_ROOT\NBBACKUPType]
@="Nero BackItUp Document"
[HKEY_CLASSES_ROOT\NBBACKUPType\shell]
[HKEY_CLASSES_ROOT\NBCOMPRESSType]
@="Nero BackItUp Compressed File"
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell]
[HKEY_CLASSES_ROOT\NBJOBType]
@="Nero BackItUp Job"
[HKEY_CLASSES_ROOT\NBJOBType\shell]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document]
@="Nero Cover Designer Document"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template]
@="Nero Cover Designer Template"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell]
[HKEY_CLASSES_ROOT\NeroCDCoverType]
@="Nero CD Cover"
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell]
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe]
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell]
@="open"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Data.nct"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Audio_Content.nct"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\NeroCoverDesigner_fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\CoverEdCtrl.ocx"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero BackItUp\\NeroBackItUp_Fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart_fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"=dword:00000001
[HKEY_CLASSES_ROOT\.pld]
@="MsgPlus.PrefPack"
[HKEY_CLASSES_ROOT\.ple]
@="MsgPlus.Encrypted"
[HKEY_CLASSES_ROOT\.plp]
@="MsgPlus.SoundPack"
[HKEY_CLASSES_ROOT\.plsc]
@="MsgPlus.ScriptPack"
[HKEY_CLASSES_ROOT\.plsk]
@="MsgPlus.SkinPack"
[HKEY_CLASSES_ROOT\OISbmpfile]
@=""
[HKEY_CLASSES_ROOT\OISemffile]
@=""
[HKEY_CLASSES_ROOT\OISgiffile]
@=""
[HKEY_CLASSES_ROOT\OISjpegfile]
@=""
[HKEY_CLASSES_ROOT\OISpngfile]
@=""
[HKEY_CLASSES_ROOT\OIStiffile]
@=""
[HKEY_CLASSES_ROOT\OISwmffile]
@=""
[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]
[HKEY_CLASSES_ROOT\WMPCD]
[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ols]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ols\OpenWithList]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf\OpenWithList]
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho]
@="EoBho Class"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho\CLSID]
@="{64F56FC1-1272-44CD-BA6E-39723696E350}"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho\CurVer]
@="EoRezoBHO.EoBho.1"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1]
@="EoBho Class"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1\CLSID]
@="{64F56FC1-1272-44CD-BA6E-39723696E350}"
[HKEY_CLASSES_ROOT\NBBACKUPType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\backitup.exe,2"
[HKEY_CLASSES_ROOT\NBBACKUPType\shell\open]
[HKEY_CLASSES_ROOT\NBBACKUPType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\backitup.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NBCOMPRESSType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\nbr.exe,0"
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open]
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbr.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NBJOBType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe,0"
[HKEY_CLASSES_ROOT\NBJOBType\shell\open]
[HKEY_CLASSES_ROOT\NBJOBType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe\" \"%1\""
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" /dde"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" /dde"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero.AutoPlay2]
[HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell]
[HKEY_CLASSES_ROOT\NeroCDCoverType\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open]
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}]
@="HDSPPropPage Class"
[HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
[HKEY_CLASSES_ROOT\CLSID\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}]
@="NeroWmpBG Class"
[HKEY_CLASSES_ROOT\CLSID\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}]
@="CoverEdCtrl Control"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\Control]
@=""
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\InprocServer32]
@="C:\\PROGRA~1\\Ahead\\COVERD~1\\COVERE~1.OCX"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\MiscStatus]
@="0"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\MiscStatus\1]
@="131473"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\ProgID]
@="COVEREDCTRL.CoverEdCtrl.1"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\ToolboxBitmap32]
@="C:\\PROGRA~1\\Ahead\\COVERD~1\\COVERE~1.OCX, 103"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\TypeLib]
@="{8EFB3D26-D0BA-429A-9BC7-1800E48E7068}"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\Version]
@="1.0"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\ProgID]
@="MDNeroBurnPlugin.MDNeroBurnPlugin.1"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\Programmable]
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\VersionIndependentProgID]
@="MDNeroBurnPlugin.MDNeroBurnPlugin"
[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe]
[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe\shell]
"FriendlyCache"="Lexmark Scan & Copy Control Program"
[HKEY_CLASSES_ROOT\Applications\moviemk.exe]
[HKEY_CLASSES_ROOT\Applications\moviemk.exe\shell]
"FriendlyCache"="Movie Maker"
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell\open]
@="&Ouvrir"
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero PhotoSnap\\PhotoSnapViewer.exe\" \"%1\""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\BackItUp.EXE]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"
"Path"="C:\\Program Files\\Ahead\\Nero BackItUp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\NCoverEd.exe]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"
"Path"="C:\\Program Files\\Ahead\\CoverDesigner"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\NeroStartSmart.exe]
@="C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"
"Path"="C:\\Program Files\\Ahead\\Nero StartSmart"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WMPBurn.exe]
@="C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"
"Path"="C:\\Program Files\\Ahead\\WMPBurn"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QHEADLES\\"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QSIGNOFF\\"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\THQ\\Le Monde de Nemo\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\THQ\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\MSN Messenger\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Google Updater]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,b0,27,00,00,00,00,00,c0,4c,1a,\
a1,97,86,c8,01,65,08,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,65,00,78,00,6d,\
00,61,00,72,00,6b,00,58,00,38,00,34,00,2d,00,58,00,38,00,35,00,5c,00,41,00,\
72,00,74,00,63,00,6f,00,70,00,79,00,35,00,35,00,2e,00,65,00,78,00,65,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Neuf_Kit]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,a0,d0,00,00,00,00,00,c0,c2,53,\
65,15,85,c8,01,40,08,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,75,00,66,\
00,5c,00,4b,00,69,00,74,00,5c,00,39,00,6c,00,61,00,75,00,6e,00,63,00,68,00,\
2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,a0,14,02,00,00,00,00,a0,6a,5f,\
20,94,86,c8,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,47,00,6f,00,6f,00,67,\
00,6c,00,65,00,5c,00,47,00,6f,00,6f,00,67,00,6c,00,65,00,20,00,45,00,61,00,\
72,00,74,00,68,00,5c,00,67,00,6f,00,6f,00,67,00,6c,00,65,00,65,00,61,00,72,\
00,74,00,68,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.cdc]
@="NeroCDCoverType"
[HKEY_CLASSES_ROOT\.nbi]
@="NBBACKUPType"
[HKEY_CLASSES_ROOT\.ncd]
@="Nero Cover Designer.Document"
[HKEY_CLASSES_ROOT\.nco]
@="NBCOMPRESSType"
[HKEY_CLASSES_ROOT\.nct]
@="Nero Cover Designer.Template"
[HKEY_CLASSES_ROOT\.nji]
@="NBJOBType"
et hijckathis mode normal
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:04:36, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Pack Securite\Common\FSMA32.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Pack Securite\Common\FSMB32.EXE
C:\Program Files\Pack Securite\Common\FCH32.EXE
C:\Program Files\Pack Securite\Common\FAMEH32.EXE
C:\Program Files\Pack Securite\FSPC\fspc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Pack Securite\FSAUA\program\fsus.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 10:35:57 17/03/2008
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B8705110-D7BE-41E8-B4C6-F47AFE990462}\RP141\A0159902.exe -> Not-A-Virus.Hacktool.EvID : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@overture[1].txt -> TrackingCookie.Overture : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@argenius.solution.weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\jim\Cookies\jim@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
Fin du rapport
s rapports : avg , cclean, clean , ( hijackthis mode normal )
[b]SDFix: Version 1.158 /b
Run by jim on 17/03/2008 at 11:30
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\jim\Bureau\SDFix
[b]Checking Services /b:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 11:41:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eChanblard"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
"C:\\Documents and Settings\\jim\\Local Settings\\Temp\\Rar$EX01.377\\emule\\eMule.exe"="C:\\Documents and Settings\\jim\\Local Settings\\Temp\\Rar$EX01.377\\emule\\eMule.exe:*:Disabled:eMule"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[b]Remaining Files /b:
File Backups: - C:\DOCUME~1\jim\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Fri 14 Mar 2008 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sun 4 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 5 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 14 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT18.tmp"
[b]Finished!/b
AntiVir PersonalEdition Classic
Report file date: lundi 17 mars 2008 10:39
Scanning for 1149639 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: jim
Computer name: JIM-AE4D62D1214
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 07:47:04
ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 07:47:04
ANTIVIR3.VDF : 7.0.3.34 182784 Bytes 17/03/2008 07:47:04
AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 17/03/2008 07:47:05
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 17/03/2008 07:47:06
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 17 mars 2008 10:39
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
16 processes with 16 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '20' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\afocef.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d44a2.qua'!
C:\WINDOWS\system32\aldxvbbccb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484244ac.qua'!
C:\WINDOWS\system32\atzjktd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485844b9.qua'!
C:\WINDOWS\system32\avjimca.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844bd.qua'!
C:\WINDOWS\system32\bdujibxue.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485344ac.qua'!
C:\WINDOWS\system32\bwljrnmh.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484a44c1.qua'!
C:\WINDOWS\system32\cltufbjcp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244bb.qua'!
C:\WINDOWS\system32\cmboojrkdq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484044bd.qua'!
C:\WINDOWS\system32\cpvhmaalyp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485444c4.qua'!
C:\WINDOWS\system32\creaylauj.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484344c7.qua'!
C:\WINDOWS\system32\cvqizomwy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44cd.qua'!
C:\WINDOWS\system32\dxecyr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484344df.qua'!
C:\WINDOWS\system32\dxhtuox.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484644df.qua'!
C:\WINDOWS\system32\dyjgngopk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844e1.qua'!
C:\WINDOWS\system32\eprxjyi.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485044da.qua'!
C:\WINDOWS\system32\eyrdejsrqa.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485044e5.qua'!
C:\WINDOWS\system32\fhqnnss.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44d5.qua'!
C:\WINDOWS\system32\fmffczb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444dc.qua'!
C:\WINDOWS\system32\fohbajy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484644de.qua'!
C:\WINDOWS\system32\ftkyznvw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484944e5.qua'!
C:\WINDOWS\system32\gkhkzub.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '493af6f7.qua'!
C:\WINDOWS\system32\gtmkyik.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b44e8.qua'!
C:\WINDOWS\system32\gwtyzunlt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244ec.qua'!
C:\WINDOWS\system32\hwotjzt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d44ee.qua'!
C:\WINDOWS\system32\hxsqmrbgl.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485144f0.qua'!
C:\WINDOWS\system32\iokdiyykd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484944ee.qua'!
C:\WINDOWS\system32\iqfaoqm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444f3.qua'!
C:\WINDOWS\system32\irssbbykz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485144f6.qua'!
C:\WINDOWS\system32\iuxxbos.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485644fa.qua'!
C:\WINDOWS\system32\jbjujwzdzk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484844e9.qua'!
C:\WINDOWS\system32\jeaifmmijs.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f44ec.qua'!
C:\WINDOWS\system32\jgnvejci.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484c44ef.qua'!
C:\WINDOWS\system32\jiqroklaa.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f44f2.qua'!
C:\WINDOWS\system32\jltazv.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485244f6.qua'!
C:\WINDOWS\system32\jpayieuvo.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f44fb.qua'!
C:\WINDOWS\system32\jqfmcuz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484444fc.qua'!
C:\WINDOWS\system32\jypyhir.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e4505.qua'!
C:\WINDOWS\system32\jzbjtio.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48404507.qua'!
C:\WINDOWS\system32\kprlhqqva.exe
[DETECTION] Is the Trojan horse TR/Agent.306688
[INFO] The file was moved to '48504501.qua'!
C:\WINDOWS\system32\lbpzcdobjw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e44f5.qua'!
C:\WINDOWS\system32\ldnuciil.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484c44f7.qua'!
C:\WINDOWS\system32\lezludsqgz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485844f9.qua'!
C:\WINDOWS\system32\ljohtjvjd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d4504.qua'!
C:\WINDOWS\system32\llhogfgugh.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48464507.qua'!
C:\WINDOWS\system32\lprcwfd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4850450d.qua'!
C:\WINDOWS\system32\nbuujob.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4853451a.qua'!
C:\WINDOWS\system32\nftiig.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524522.qua'!
C:\WINDOWS\system32\ngrdhp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48504524.qua'!
C:\WINDOWS\system32\nktuznz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524529.qua'!
C:\WINDOWS\system32\npxugofyt.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4856452f.qua'!
C:\WINDOWS\system32\nybobqtx.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4840453c.qua'!
C:\WINDOWS\system32\pgtswy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524532.qua'!
C:\WINDOWS\system32\psqxgovyo.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f4541.qua'!
C:\WINDOWS\system32\pvfqqqi.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48444545.qua'!
C:\WINDOWS\system32\qayajlphez.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574532.qua'!
C:\WINDOWS\system32\qjjblpx.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4848453c.qua'!
C:\WINDOWS\system32\qjmauvuxd.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b453d.qua'!
C:\WINDOWS\system32\qvlpjnlfp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484a454a.qua'!
C:\WINDOWS\system32\recrszgj.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4841453d.qua'!
C:\WINDOWS\system32\rvyqknn.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574552.qua'!
C:\WINDOWS\system32\sftodny.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48524549.qua'!
C:\WINDOWS\system32\slbolsg.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48404552.qua'!
C:\WINDOWS\system32\sodqsy.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48424556.qua'!
C:\WINDOWS\system32\syajej.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f456d.qua'!
C:\WINDOWS\system32\tfdsvblal.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4842455e.qua'!
C:\WINDOWS\system32\ugarougm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '483f4565.qua'!
C:\WINDOWS\system32\ukhfgikwu.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4846456a.qua'!
C:\WINDOWS\system32\vdhhzcjrri.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '493af743.qua'!
C:\WINDOWS\system32\vixmfkzxxz.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48564570.qua'!
C:\WINDOWS\system32\vqqlwm.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484f457b.qua'!
C:\WINDOWS\system32\vuoijvw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484d4580.qua'!
C:\WINDOWS\system32\vweajw.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48434583.qua'!
C:\WINDOWS\system32\wipsnyp.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484e457b.qua'!
C:\WINDOWS\system32\wjebsmb.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4843457d.qua'!
C:\WINDOWS\system32\xmxjkq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4856458d.qua'!
C:\WINDOWS\system32\xnwapnxgr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4855458f.qua'!
C:\WINDOWS\system32\xoiuxcab.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48474591.qua'!
C:\WINDOWS\system32\yocsxrc.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48414593.qua'!
C:\WINDOWS\system32\ypkqogej.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48494595.qua'!
C:\WINDOWS\system32\yryawxomf.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574598.qua'!
C:\WINDOWS\system32\ywmruatyq.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '484b459e.qua'!
C:\WINDOWS\system32\zbjjev.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48484589.qua'!
C:\WINDOWS\system32\zdzwjbu.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4858458c.qua'!
C:\WINDOWS\system32\zfsnhbr.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '4851458e.qua'!
C:\WINDOWS\system32\zgyizwny.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '48574590.qua'!
C:\WINDOWS\system32\zxvads.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485445a2.qua'!
C:\WINDOWS\system32\zytindzk.exe
[DETECTION] Is the Trojan horse TR/Dropper.Gen
[INFO] The file was moved to '485245a4.qua'!
End of the scan: lundi 17 mars 2008 11:21
Used time: 42:19 min
The scan has been done completely.
2884 Scanning directories
93785 Files were scanned
87 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
87 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
93698 Files not concerned
714 Archives were scanned
1 Warnings
0 Notes
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\COVEREDCTRL.CoverEdCtrl.1]
@="CoverEdCtrl Control"
[HKEY_CLASSES_ROOT\COVEREDCTRL.CoverEdCtrl.1\CLSID]
@="{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin\CLSID]
@="{896E73F0-3851-11D3-AA54-00C04FD22F8C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin\CurVer]
@="MDNeroBurnPlugin.MDNeroBurnPlugin.1"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin.1]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.MDNeroBurnPlugin.1\CLSID]
@="{896E73F0-3851-11D3-AA54-00C04FD22F8C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage]
@="HDSPPropPage Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage\CLSID]
@="{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage\CurVer]
@="MDNeroBurnPlugin.PropPage.1"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage.1]
@="PropPage Class"
[HKEY_CLASSES_ROOT\MDNeroBurnPlugin.PropPage.1\CLSID]
@="{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}"
[HKEY_CLASSES_ROOT\NBBACKUPType]
@="Nero BackItUp Document"
[HKEY_CLASSES_ROOT\NBBACKUPType\shell]
[HKEY_CLASSES_ROOT\NBCOMPRESSType]
@="Nero BackItUp Compressed File"
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell]
[HKEY_CLASSES_ROOT\NBJOBType]
@="Nero BackItUp Job"
[HKEY_CLASSES_ROOT\NBJOBType\shell]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document]
@="Nero Cover Designer Document"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template]
@="Nero Cover Designer Template"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell]
[HKEY_CLASSES_ROOT\NeroCDCoverType]
@="Nero CD Cover"
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell]
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe]
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell]
@="open"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Data.nct"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Audio_Content.nct"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\NeroCoverDesigner_fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\CoverEdCtrl.ocx"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero BackItUp\\NeroBackItUp_Fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart_fra.chm"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"=dword:00000001
[HKEY_CLASSES_ROOT\.pld]
@="MsgPlus.PrefPack"
[HKEY_CLASSES_ROOT\.ple]
@="MsgPlus.Encrypted"
[HKEY_CLASSES_ROOT\.plp]
@="MsgPlus.SoundPack"
[HKEY_CLASSES_ROOT\.plsc]
@="MsgPlus.ScriptPack"
[HKEY_CLASSES_ROOT\.plsk]
@="MsgPlus.SkinPack"
[HKEY_CLASSES_ROOT\OISbmpfile]
@=""
[HKEY_CLASSES_ROOT\OISemffile]
@=""
[HKEY_CLASSES_ROOT\OISgiffile]
@=""
[HKEY_CLASSES_ROOT\OISjpegfile]
@=""
[HKEY_CLASSES_ROOT\OISpngfile]
@=""
[HKEY_CLASSES_ROOT\OIStiffile]
@=""
[HKEY_CLASSES_ROOT\OISwmffile]
@=""
[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]
[HKEY_CLASSES_ROOT\WMPCD]
[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ols]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ols\OpenWithList]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vdf\OpenWithList]
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho]
@="EoBho Class"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho\CLSID]
@="{64F56FC1-1272-44CD-BA6E-39723696E350}"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho\CurVer]
@="EoRezoBHO.EoBho.1"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1]
@="EoBho Class"
[HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1\CLSID]
@="{64F56FC1-1272-44CD-BA6E-39723696E350}"
[HKEY_CLASSES_ROOT\NBBACKUPType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\backitup.exe,2"
[HKEY_CLASSES_ROOT\NBBACKUPType\shell\open]
[HKEY_CLASSES_ROOT\NBBACKUPType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\backitup.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NBCOMPRESSType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\nbr.exe,0"
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open]
[HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbr.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NBJOBType\DefaultIcon]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe,0"
[HKEY_CLASSES_ROOT\NBJOBType\shell\open]
[HKEY_CLASSES_ROOT\NBJOBType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero BackItUp\\nbj.exe\" \"%1\""
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" /dde"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open]
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" /dde"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec\Application]
@="CoverDes"
[HKEY_CLASSES_ROOT\Nero.AutoPlay2]
[HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell]
[HKEY_CLASSES_ROOT\NeroCDCoverType\DefaultIcon]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe,1"
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open]
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\command]
@="\"C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe\" \"%1\""
[HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\ddeexec]
@="[open(\"%1\")]"
[HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}]
@="HDSPPropPage Class"
[HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
[HKEY_CLASSES_ROOT\CLSID\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}]
@="NeroWmpBG Class"
[HKEY_CLASSES_ROOT\CLSID\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}]
@="CoverEdCtrl Control"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\Control]
@=""
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\InprocServer32]
@="C:\\PROGRA~1\\Ahead\\COVERD~1\\COVERE~1.OCX"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\MiscStatus]
@="0"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\MiscStatus\1]
@="131473"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\ProgID]
@="COVEREDCTRL.CoverEdCtrl.1"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\ToolboxBitmap32]
@="C:\\PROGRA~1\\Ahead\\COVERD~1\\COVERE~1.OCX, 103"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\TypeLib]
@="{8EFB3D26-D0BA-429A-9BC7-1800E48E7068}"
[HKEY_CLASSES_ROOT\CLSID\{59FA1D1E-3B4C-4311-BB1B-7BF16C607388}\Version]
@="1.0"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}]
@="MDNeroBurnPlugin Class"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\InprocServer32]
@="C:\\Program Files\\Ahead\\WMPBurn\\NeroBurnPlugin.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\ProgID]
@="MDNeroBurnPlugin.MDNeroBurnPlugin.1"
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\Programmable]
[HKEY_CLASSES_ROOT\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F8C}\VersionIndependentProgID]
@="MDNeroBurnPlugin.MDNeroBurnPlugin"
[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe]
[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe\shell]
"FriendlyCache"="Lexmark Scan & Copy Control Program"
[HKEY_CLASSES_ROOT\Applications\moviemk.exe]
[HKEY_CLASSES_ROOT\Applications\moviemk.exe\shell]
"FriendlyCache"="Movie Maker"
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell\open]
@="&Ouvrir"
[HKEY_CLASSES_ROOT\Applications\PhotoSnapViewer.exe\shell\open\command]
@="\"C:\\Program Files\\Ahead\\Nero PhotoSnap\\PhotoSnapViewer.exe\" \"%1\""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\BackItUp.EXE]
@="C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"
"Path"="C:\\Program Files\\Ahead\\Nero BackItUp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\NCoverEd.exe]
@="C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"
"Path"="C:\\Program Files\\Ahead\\CoverDesigner"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\NeroStartSmart.exe]
@="C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"
"Path"="C:\\Program Files\\Ahead\\Nero StartSmart"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WMPBurn.exe]
@="C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"
"Path"="C:\\Program Files\\Ahead\\WMPBurn"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QHEADLES\\"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QSIGNOFF\\"="1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\THQ\\Le Monde de Nemo\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\THQ\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\MSN Messenger\\"=""
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Google Updater]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,b0,27,00,00,00,00,00,c0,4c,1a,\
a1,97,86,c8,01,65,08,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,65,00,78,00,6d,\
00,61,00,72,00,6b,00,58,00,38,00,34,00,2d,00,58,00,38,00,35,00,5c,00,41,00,\
72,00,74,00,63,00,6f,00,70,00,79,00,35,00,35,00,2e,00,65,00,78,00,65,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Neuf_Kit]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,a0,d0,00,00,00,00,00,c0,c2,53,\
65,15,85,c8,01,40,08,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,75,00,66,\
00,5c,00,4b,00,69,00,74,00,5c,00,39,00,6c,00,61,00,75,00,6e,00,63,00,68,00,\
2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,a0,14,02,00,00,00,00,a0,6a,5f,\
20,94,86,c8,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,47,00,6f,00,6f,00,67,\
00,6c,00,65,00,5c,00,47,00,6f,00,6f,00,67,00,6c,00,65,00,20,00,45,00,61,00,\
72,00,74,00,68,00,5c,00,67,00,6f,00,6f,00,67,00,6c,00,65,00,65,00,61,00,72,\
00,74,00,68,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.cdc]
@="NeroCDCoverType"
[HKEY_CLASSES_ROOT\.nbi]
@="NBBACKUPType"
[HKEY_CLASSES_ROOT\.ncd]
@="Nero Cover Designer.Document"
[HKEY_CLASSES_ROOT\.nco]
@="NBCOMPRESSType"
[HKEY_CLASSES_ROOT\.nct]
@="Nero Cover Designer.Template"
[HKEY_CLASSES_ROOT\.nji]
@="NBJOBType"
et hijckathis mode normal
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:04:36, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Pack Securite\Common\FSMA32.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Pack Securite\Common\FSMB32.EXE
C:\Program Files\Pack Securite\Common\FCH32.EXE
C:\Program Files\Pack Securite\Common\FAMEH32.EXE
C:\Program Files\Pack Securite\FSPC\fspc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Pack Securite\FSAUA\program\fsus.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
rapport clean
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 17/03/2008 a 12:42:12,28
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de "C:\Documents and Settings\jim\Application Data\MessengerSkinner\"
*** Suppression des fichiers dans C:\Program Files
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 17/03/2008 a 12:42:12,28
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de "C:\Documents and Settings\jim\Application Data\MessengerSkinner\"
*** Suppression des fichiers dans C:\Program Files
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 11:41:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Rootkit scan 2008-03-17 11:41:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
j'ai tout suivi peut etre pas dans l'ordre mai bon voila tous les rapports sont postés en mode sans echec et en mode normal il m'a fallu un certain temps pour tous faire et surtout pour comprendre le fonctionnement des logiciels ( et encore pas tout compris ) lol
peut etre pas dans l'ordre
Il y a quelque chose qui te bloques pour ne pas faire les choses dans l'ordre ou on te les indiques?
DllD t'as demandé de faire un effort, pourquoi ne le fais-tu pas ?
Un helper suit une logique, si tu ne collabores pas à 100 % avec lui ou elle, tu compromet cette logique.
Comprend que nous n'avons pas les doigts sur ton clavier et que la moindre fausse manœuvre peut entrainer des conséquences.
Les conséquences peuvent-être
1) Une désinfection non totale.
2) Un plantage irrécupérable de ta machine.
3) Un abandon du helper.
N'essaye pas de comprendre pour l'instant ce qu'il te fait faire, fait le.
Pour comprendre, il y a des milliers de topics de déverminage qui t'aideront à le faire. Mais attends que ta vaisselle soit terminée
Pour finir et ce n'est pas méchant, concentre toi sur les procédures, ne dis que l'essentiel.
-
Il y a quelque chose qui te bloques pour ne pas faire les choses dans l'ordre ou on te les indiques?
DllD t'as demandé de faire un effort, pourquoi ne le fais-tu pas ?
Un helper suit une logique, si tu ne collabores pas à 100 % avec lui ou elle, tu compromet cette logique.
Comprend que nous n'avons pas les doigts sur ton clavier et que la moindre fausse manœuvre peut entrainer des conséquences.
Les conséquences peuvent-être
1) Une désinfection non totale.
2) Un plantage irrécupérable de ta machine.
3) Un abandon du helper.
N'essaye pas de comprendre pour l'instant ce qu'il te fait faire, fait le.
Pour comprendre, il y a des milliers de topics de déverminage qui t'aideront à le faire. Mais attends que ta vaisselle soit terminée
Pour finir et ce n'est pas méchant, concentre toi sur les procédures, ne dis que l'essentiel.
-
ben c se que j'ai fait mai j'espere avoir fais com il faut . la ya tout ce qu'il me demandais de faire apres je sais pas si c bon
ok compris l'abandon de la personne qui aide ,
mais quand on est pas calée en informatique il est normal d'avoir des difficultées a faire ce qu'on nous demande sinon on ne rechercherais pas d'aide dans le forum non ? malgré les efforts je pense ne pas etre la seule ( enfin j'espere ) a avoi des difficultées a executer des consignes informatiques surtout quand on y connai rien non ?
mais quand on est pas calée en informatique il est normal d'avoir des difficultées a faire ce qu'on nous demande sinon on ne rechercherais pas d'aide dans le forum non ? malgré les efforts je pense ne pas etre la seule ( enfin j'espere ) a avoi des difficultées a executer des consignes informatiques surtout quand on y connai rien non ?