Pc infecté

Résolu
chrisetsylvain Messages postés 112 Statut Membre -  
ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour, je voudrais savoir si quelqu'un peux m'aider car je crois que mon pc est infecté, il s'éteint seul Firefox parfois ne s'ouvre pas mes applications se ferment également seules il est de plus en plus long et parfois lorsque je l'allume je n'ai que mon fond d'écran
je poste un rapport hi-jackthis et vous dit merci d'avance pour votre aide
Configuration: Windows XP
Firefox 2.0.0.12


Logfile of HijackThis v1.99.1
Scan saved at 19:24:46, on 22/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\program files\a-squared free\a2service.exe
C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
C:\Program Files\Acer\Acer eConsole\MediaSync.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CB28A3A-BD0E-4801-8E60-4857FB6EAEB8} - C:\WINDOWS\system32\sstqp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {ED120D76-BF31-412C-A99B-783C6676E128} - C:\WINDOWS\system32\cbxwttq.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cbxwttq - C:\WINDOWS\SYSTEM32\cbxwttq.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

merci à tous

15 réponses

  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    Télécharge sur le Bureau.
    http://www.atribune.org/ccount/click.php?id=4

    => Double-clic VundoFix.exe.
    => Clic OK
    => Attendre le redemarrage de Vundofix
    => Clic Scan for Vundo
    => Le scan est assez long , à la fin
    => Clic Remove Vundo
    => Puis yes
    => Le Bureau disparaît un moment lors de la suppression des fichiers.
    => Message shutdown
    => clic OK
    => Redémarrage auto
    => copier le rapport qui est dans C:vundofix.txt

    ensuite
    Télécharge Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    et sauvegarde le sur ton bureau et pas ailleurs!

    Double-clic sur combofix,
    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

    @+
    0
    1. chris
       
      salut !
      tout d'abord merci pour ton aide
      je voulais te poser une question j'ai passé vundo et à la fin du scan tu m'as dit de faire remove vundo hors à l'écran j'ai fix vundo c'est pareil ?je clic fix vundo au lieu de remove vundo ?
      merci à l'avance comme tu le vois je n'y connais pas grand chose désolé !
      0
  2. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    bonsoir
    oui clic sur fix vundo
    @+
    0
    1. chris
       
      bonjour,
      voilà je te poste mon rapport vundo fix :

      VundoFix V7.0.3

      Scan started at 08:09:04 25/03/2008

      Listing files found while scanning....

      C:\windows\system32\pqtss.ini
      C:\windows\system32\pqtss.ini2
      C:\windows\system32\sstqp.dll

      Beginning removal...

      Attempting to delete C:\windows\system32\pqtss.ini
      C:\windows\system32\pqtss.ini Has been deleted!

      Attempting to delete C:\windows\system32\pqtss.ini2
      C:\windows\system32\pqtss.ini2 Has been deleted!

      Attempting to delete C:\windows\system32\sstqp.dll
      C:\windows\system32\sstqp.dll Has been deleted!

      Performing Repairs to the registry.
      Done!
      0
    2. chris
       
      j'ai également passé combofix je l'ai fais deux fois car j'ai eu un bug je t'explique la première fois je l'ai mis en route j'ai entendu 2 bips courts puis il a démarré et mon pc c'est éteinds avant que combofix ne fasse son rapport il a redémarrer tous seul la fenêtre comofix était là et affichait que le rapport était en cour de préparation elle a disparu mais pas de rapport affiché.

      j'ai attendu un moment et j'ai refait combofix qui cette fois a générer un rapport sans que rien ne s'éteigne ou ne bug je le poste :

      ComboFix 08-03-24.2 - christelle 2008-03-26 8:09:58.2 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.402 [GMT 1:00]
      Endroit: C:\Documents and Settings\christelle\Bureau\ComboFix.exe

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      ---- Previous Run -------
      .
      C:\Documents and Settings\christelle\Application Data\DriveCleaner 2006 Free
      C:\Documents and Settings\christelle\Application Data\DriveCleaner 2006 Free\Logs\update.log
      C:\Documents and Settings\christelle\Application Data\inst.exe
      C:\WINDOWS\system32\autorun.ini
      C:\WINDOWS\system32\mcrh.tmp
      C:\WINDOWS\system32\UpMedia

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_IPRIP
      -------\Service_Iprip


      ((((((((((((((((((((((((((((( Fichiers créés 2008-02-26 to 2008-03-26 ))))))))))))))))))))))))))))))))))))
      .

      2008-03-25 08:09 . 2008-03-26 07:33 <REP> d-------- C:\VundoFix Backups
      2008-03-16 12:16 . 2008-03-16 12:16 <REP> d-------- C:\LILIMATH
      2008-03-13 08:59 . 2008-03-13 08:59 <REP> d-------- C:\Program Files\PopCap Games
      2008-03-13 08:59 . 2008-03-13 08:59 51,355 --a------ C:\WINDOWS\system32\muzika.xm
      2008-03-11 08:55 . 2008-03-17 12:18 69 --a------ C:\WINDOWS\NeroDigital.ini
      2008-03-09 19:58 . 2004-07-26 16:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
      2008-03-09 19:58 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
      2008-03-09 19:58 . 2004-03-02 16:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
      2008-03-09 19:58 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
      2008-03-09 19:58 . 2004-03-02 16:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
      2008-03-07 14:03 . 2008-03-07 14:03 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
      2008-03-07 14:03 . 2008-03-07 14:03 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
      2008-03-07 13:40 . 2008-03-07 13:40 13,035 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
      2008-03-07 13:40 . 2008-03-07 13:40 1,358 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
      2008-03-07 13:39 . 2008-03-07 13:39 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
      2008-03-07 13:39 . 2008-03-07 13:39 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
      2008-03-07 13:39 . 2008-03-07 13:39 39,984 --a------ C:\WINDOWS\system32\drivers\symids.sys
      2008-03-07 13:39 . 2008-03-07 13:39 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
      2008-03-07 13:39 . 2008-03-07 13:39 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
      2008-03-07 13:39 . 2008-03-07 13:39 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
      2008-03-07 13:39 . 2008-03-07 13:39 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-03-25 19:06 --------- d-----w C:\Program Files\WinamaxPoker
      2008-03-25 06:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
      2008-03-24 15:03 --------- d-----w C:\Program Files\Java
      2008-03-22 21:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-03-22 18:25 --------- d-----w C:\Program Files\Hijackthis Version Française
      2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Toolbar
      2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Favorites
      2008-03-22 13:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
      2008-03-22 13:08 --------- d-----w C:\Program Files\QuickTime
      2008-03-22 13:07 --------- d-----w C:\Program Files\Norton AntiVirus
      2008-03-22 13:06 --------- d-----w C:\Program Files\MSN Messenger
      2008-03-22 12:59 --------- d-----w C:\Program Files\Google
      2008-03-22 12:57 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
      2008-03-22 12:50 --------- d-----w C:\Program Files\a-squared Free
      2008-03-12 10:17 --------- d-----w C:\Program Files\RegistrySmart
      2008-03-09 18:58 --------- d-----w C:\Program Files\Fichiers communs\Ahead
      2008-03-09 18:58 --------- d-----w C:\Program Files\Ahead
      2008-03-06 20:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
      2008-03-06 20:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
      2008-03-06 20:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
      2008-03-05 12:42 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
      2008-03-05 12:42 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
      2008-03-05 12:42 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
      2008-02-17 17:44 691,545 ----a-w C:\WINDOWS\unins000.exe
      2008-02-10 14:14 --------- d-----w C:\Program Files\directx
      2008-02-10 14:13 --------- d-----w C:\Program Files\Commandos II
      2008-02-10 14:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-02-01 14:00 --------- d-----w C:\Program Files\Norton Security Scan
      2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
      2007-10-09 08:20 10 ----a-w C:\Program Files\.autoreg
      2007-07-04 11:14 4,704 ----a-w C:\Program Files\satsukidecodersettings.ini
      2007-07-04 11:13 680 ----a-w C:\Program Files\mpc2.reg
      2007-07-04 11:13 558 ----a-w C:\Program Files\mpc1.reg
      2007-07-04 11:13 32,422 ----a-w C:\Program Files\ffdssetts.reg
      2007-07-04 11:13 30,772 ----a-w C:\Program Files\ffdsvsetts.reg
      2007-07-04 11:13 3,476 ----a-w C:\Program Files\mpc7.reg
      2007-07-04 11:13 3,026 ----a-w C:\Program Files\mpc3.reg
      2007-07-04 11:13 236 ----a-w C:\Program Files\mpc4.reg
      2007-07-04 11:13 18,156 ----a-w C:\Program Files\mpc6.reg
      2007-07-04 11:13 16,290 ----a-w C:\Program Files\mpc5.reg
      2007-07-04 11:13 13,366 ----a-w C:\Program Files\ffdsasetts.reg
      2007-05-30 16:34 47,360 ----a-w C:\Documents and Settings\christelle\Application Data\pcouffin.sys
      2007-04-06 06:23 3,672,408 ----a-w C:\Documents and Settings\christelle\watch.exe
      2007-04-06 06:23 10,166,182 ----a-w C:\Documents and Settings\christelle\NBR6606FRA.exe
      2007-04-04 11:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
      2007-02-25 19:05 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6962.dat
      2007-02-25 18:49 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb1478.dat
      2007-02-25 17:13 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9358.dat
      2007-02-14 10:00 635,625 ----a-w C:\Documents and Settings\christelle\pays.zip
      2007-02-08 16:39 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9169.dat
      2007-02-08 16:39 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb5724.dat
      2007-02-08 16:39 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6500.dat
      2007-02-04 12:49 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6334.dat
      2007-02-04 12:46 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb41.dat
      2007-02-04 12:10 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb8467.dat
      2007-04-28 06:58 2,124,695 --sh--w C:\WINDOWS\ruwvxx.ini2
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{787E5742-9E2A-43FA-8A2E-00B8733F908E}]
      C:\WINDOWS\system32\sstqp.dll

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 06:00 15360]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 08:58 68856]
      "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.exe]
      "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
      "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
      "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
      "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15 45056]
      "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 06:00 59392]
      "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 12:48 425984]
      "LaunchApp"="Alaunch" []
      "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 06:00 208952]
      "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
      "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 17:00 397312]
      "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 15:07 114688]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
      "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
      "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 18:22 26248]
      "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43 286720]
      "WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2001-10-09 12:28 24576]
      "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-10-05 15:53 331830]
      "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-09-04 21:30 28738]
      "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
      "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 06:00 15360]

      C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-27 11:14:35 110592]
      Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 13:14:38 24633]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxwttq]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplicat­ions\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
      "C:\\WINDOWS\\system32\\ftp.exe"=
      "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
      "C:\\Program Files\\Outlook Express\\msimn.exe"=
      "C:\\WINDOWS\\system32\\rtcshare.exe"=
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\MSN Messenger\\livecall.exe"=
      "C:\\Documents and Settings\\enfants\\Local Settings\\Temp\\ImInstaller\\IncrediMail\\incredimail_install.exe"=
      "C:\\Program Files\\Shareaza\\Shareaza.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\­List]
      "3587:TCP"= 3587:TCP:Groupement homologue Windows
      "3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
      "6346:TCP"= 6346:TCP:shareaza
      "6346:UDP"= 6346:UDP:shareaza

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 08:00]
      R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
      R2 MMIndexer;Media Manager Indexer;C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe [1997-07-14 23:00]
      S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 16:04]
      S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" []

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

      .
      Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
      "2008-03-17 22:00:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      "2007-02-12 12:38:00 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
      - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
      "2008-03-21 12:39:22 C:\WINDOWS\Tasks\Norton AntiVirus - Analyse système complète - christelle.job"
      - C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
      "2008-03-26 06:32:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
      - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
      .
      **************************************************************************

      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-03-26 08:12:23
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      Scan terminé avec succès
      Les fichiers cachés: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iprip]
      "ServiceDll"="%SystemRoot%\System32\iprip.dll"
      .
      --------------------- DLLs a chargé sous des processus courants ---------------------

      PROCESS: C:\WINDOWS\explorer.exe
      -> C:\Program Files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
      .
      Temps d'accomplissement: 2008-03-26 8:13:05
      ComboFix-quarantined-files.txt 2008-03-26 07:13:02
      .
      2008-03-20 11:02:59 --- E O F ---

      voilà je te remercie encore et j'attends ton avis
      a+
      0
  3. chris
     
    j'ai également passé combofix je l'ai fais deux fois car j'ai eu un bug je t'explique la première fois je l'ai mis en route j'ai entendu 2 bips courts puis il a démarré et mon pc c'est éteinds avant que combofix ne fasse son rapport il a redémarrer tous seul la fenêtre comofix était là et affichait que le rapport était en cour de préparation elle a disparu mais pas de rapport affiché.

    j'ai attendu un moment et j'ai refait combofix qui cette fois a générer un rapport sans que rien ne s'éteigne ou ne bug je le poste :

    ComboFix 08-03-24.2 - christelle 2008-03-26 8:09:58.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.402 [GMT 1:00]
    Endroit: C:\Documents and Settings\christelle\Bureau\ComboFix.exe

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    C:\Documents and Settings\christelle\Application Data\DriveCleaner 2006 Free
    C:\Documents and Settings\christelle\Application Data\DriveCleaner 2006 Free\Logs\update.log
    C:\Documents and Settings\christelle\Application Data\inst.exe
    C:\WINDOWS\system32\autorun.ini
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\UpMedia

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_IPRIP
    -------\Service_Iprip

    ((((((((((((((((((((((((((((( Fichiers créés 2008-02-26 to 2008-03-26 ))))))))))))))))))))))))))))))))))))
    .

    2008-03-25 08:09 . 2008-03-26 07:33 <REP> d-------- C:\VundoFix Backups
    2008-03-16 12:16 . 2008-03-16 12:16 <REP> d-------- C:\LILIMATH
    2008-03-13 08:59 . 2008-03-13 08:59 <REP> d-------- C:\Program Files\PopCap Games
    2008-03-13 08:59 . 2008-03-13 08:59 51,355 --a------ C:\WINDOWS\system32\muzika.xm
    2008-03-11 08:55 . 2008-03-17 12:18 69 --a------ C:\WINDOWS\NeroDigital.ini
    2008-03-09 19:58 . 2004-07-26 16:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
    2008-03-09 19:58 . 2004-07-26 16:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
    2008-03-09 19:58 . 2004-07-26 16:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
    2008-03-09 19:58 . 2004-07-26 16:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
    2008-03-09 19:58 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
    2008-03-09 19:58 . 2004-03-02 16:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
    2008-03-09 19:58 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
    2008-03-09 19:58 . 2004-03-02 16:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
    2008-03-07 14:03 . 2008-03-07 14:03 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
    2008-03-07 14:03 . 2008-03-07 14:03 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
    2008-03-07 13:40 . 2008-03-07 13:40 13,035 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
    2008-03-07 13:40 . 2008-03-07 13:40 1,358 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
    2008-03-07 13:39 . 2008-03-07 13:39 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
    2008-03-07 13:39 . 2008-03-07 13:39 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
    2008-03-07 13:39 . 2008-03-07 13:39 39,984 --a------ C:\WINDOWS\system32\drivers\symids.sys
    2008-03-07 13:39 . 2008-03-07 13:39 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
    2008-03-07 13:39 . 2008-03-07 13:39 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
    2008-03-07 13:39 . 2008-03-07 13:39 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
    2008-03-07 13:39 . 2008-03-07 13:39 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-25 19:06 --------- d-----w C:\Program Files\WinamaxPoker
    2008-03-25 06:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-03-24 15:03 --------- d-----w C:\Program Files\Java
    2008-03-22 21:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-03-22 18:25 --------- d-----w C:\Program Files\Hijackthis Version Française
    2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Toolbar
    2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Favorites
    2008-03-22 13:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-03-22 13:08 --------- d-----w C:\Program Files\QuickTime
    2008-03-22 13:07 --------- d-----w C:\Program Files\Norton AntiVirus
    2008-03-22 13:06 --------- d-----w C:\Program Files\MSN Messenger
    2008-03-22 12:59 --------- d-----w C:\Program Files\Google
    2008-03-22 12:57 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-03-22 12:50 --------- d-----w C:\Program Files\a-squared Free
    2008-03-12 10:17 --------- d-----w C:\Program Files\RegistrySmart
    2008-03-09 18:58 --------- d-----w C:\Program Files\Fichiers communs\Ahead
    2008-03-09 18:58 --------- d-----w C:\Program Files\Ahead
    2008-03-06 20:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
    2008-03-06 20:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
    2008-03-06 20:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
    2008-03-05 12:42 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
    2008-03-05 12:42 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
    2008-03-05 12:42 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
    2008-02-17 17:44 691,545 ----a-w C:\WINDOWS\unins000.exe
    2008-02-10 14:14 --------- d-----w C:\Program Files\directx
    2008-02-10 14:13 --------- d-----w C:\Program Files\Commandos II
    2008-02-10 14:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-02-01 14:00 --------- d-----w C:\Program Files\Norton Security Scan
    2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    2007-10-09 08:20 10 ----a-w C:\Program Files\.autoreg
    2007-07-04 11:14 4,704 ----a-w C:\Program Files\satsukidecodersettings.ini
    2007-07-04 11:13 680 ----a-w C:\Program Files\mpc2.reg
    2007-07-04 11:13 558 ----a-w C:\Program Files\mpc1.reg
    2007-07-04 11:13 32,422 ----a-w C:\Program Files\ffdssetts.reg
    2007-07-04 11:13 30,772 ----a-w C:\Program Files\ffdsvsetts.reg
    2007-07-04 11:13 3,476 ----a-w C:\Program Files\mpc7.reg
    2007-07-04 11:13 3,026 ----a-w C:\Program Files\mpc3.reg
    2007-07-04 11:13 236 ----a-w C:\Program Files\mpc4.reg
    2007-07-04 11:13 18,156 ----a-w C:\Program Files\mpc6.reg
    2007-07-04 11:13 16,290 ----a-w C:\Program Files\mpc5.reg
    2007-07-04 11:13 13,366 ----a-w C:\Program Files\ffdsasetts.reg
    2007-05-30 16:34 47,360 ----a-w C:\Documents and Settings\christelle\Application Data\pcouffin.sys
    2007-04-06 06:23 3,672,408 ----a-w C:\Documents and Settings\christelle\watch.exe
    2007-04-06 06:23 10,166,182 ----a-w C:\Documents and Settings\christelle\NBR6606FRA.exe
    2007-04-04 11:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2007-02-25 19:05 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6962.dat
    2007-02-25 18:49 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb1478.dat
    2007-02-25 17:13 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9358.dat
    2007-02-14 10:00 635,625 ----a-w C:\Documents and Settings\christelle\pays.zip
    2007-02-08 16:39 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9169.dat
    2007-02-08 16:39 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb5724.dat
    2007-02-08 16:39 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6500.dat
    2007-02-04 12:49 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6334.dat
    2007-02-04 12:46 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb41.dat
    2007-02-04 12:10 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb8467.dat
    2007-04-28 06:58 2,124,695 --sh--w C:\WINDOWS\ruwvxx.ini2
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{787E5742-9E2A-43FA-8A2E-00B8733F908E}]
    C:\WINDOWS\system32\sstqp.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 06:00 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 08:58 68856]
    "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.exe]
    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
    "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15 45056]
    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 06:00 59392]
    "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 12:48 425984]
    "LaunchApp"="Alaunch" []
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 06:00 208952]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
    "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 17:00 397312]
    "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 15:07 114688]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
    "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 18:22 26248]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43 286720]
    "WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2001-10-09 12:28 24576]
    "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-10-05 15:53 331830]
    "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-09-04 21:30 28738]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
    "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 06:00 15360]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-27 11:14:35 110592]
    Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 13:14:38 24633]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxwttq]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
    "C:\\WINDOWS\\system32\\ftp.exe"=
    "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "C:\\Program Files\\Outlook Express\\msimn.exe"=
    "C:\\WINDOWS\\system32\\rtcshare.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Documents and Settings\\enfants\\Local Settings\\Temp\\ImInstaller\\IncrediMail\\incredimail_install.exe"=
    "C:\\Program Files\\Shareaza\\Shareaza.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3587:TCP"= 3587:TCP:Groupement homologue Windows
    "3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
    "6346:TCP"= 6346:TCP:shareaza
    "6346:UDP"= 6346:UDP:shareaza

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest"= 1 (0x1)

    R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 08:00]
    R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
    R2 MMIndexer;Media Manager Indexer;C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe [1997-07-14 23:00]
    S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 16:04]
    S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
    S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
    S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
    S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
    S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" []

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-03-17 22:00:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-02-12 12:38:00 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
    - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
    "2008-03-21 12:39:22 C:\WINDOWS\Tasks\Norton AntiVirus - Analyse système complète - christelle.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
    "2008-03-26 06:32:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
    - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-26 08:12:23
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iprip]
    "ServiceDll"="%SystemRoot%\System32\iprip.dll"
    .
    --------------------- DLLs a chargé sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
    .
    Temps d'accomplissement: 2008-03-26 8:13:05
    ComboFix-quarantined-files.txt 2008-03-26 07:13:02
    .
    2008-03-20 11:02:59 --- E O F ---

    voilà je te remercie encore et j'attends ton avis
    a+
    0
  4. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    selectionne ceci

    Driver::
    int15.sys

    registry::

    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{787E5742-9E2A-43FA-8A2E-00B8733F908E}]

    File::
    C:\WINDOWS\ruwvxx.ini2
    C:\Acer\Empowering Technology\eRecovery\int15.sys

    * Copie le texte sélectionné (CTRL+C).
    * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
    * Veille à ce que Retour à la ligne ne soit pas coché dans Format.
    * Colle le texte copié dans ce bloc-notes (CTRL+V).
    * Sauvegarde ce fichier sous le nom de CFScript.txt
    * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
    * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
    Ne touche à rien tant que le scan n'est pas terminé.
    * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

    ensuite

    Télécharge Brute Force Uninstaller (de Merijn) ici: http://www.merijn.org/files/bfu.zip
    Créé un nouveau dossier directement à la racine de ton disque dur ou l'endroit qui te convient, nomme ce dossier BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (par exemple C:\BFU)
    Ensuite, télécharge Winsoftware.bfu (de lazzzy) :
    Fais un clik droit ici : : http://www.alt-shift-return.org/Info/Fichiers/Winsoftware.bfu
    et choisis "Enregistrer la cible sous..." afin de télécharger Winsoftware.bfu (delazzzy).
    Sauvegarde dans le dossier créé (C:\BFU).
    **Note : si tu utilises Internet Explorer ; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers".

    Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : Winsoftware.bfu et BFU.exe (très important).

    -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-

    Tu as une démo animée ici (merci balltrap34):
    http://perso.orange.fr/rginformatique/section%20virus/bfu%20demo.htm
    _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
    Lance "Brute Force Uninstaller" en double-cliquant BFU.exe (Dans le dossier C:\BFU)
    - Clique sur le petit dossier jaune, et clique sur : Winsoftware.bfu
    - Coches la case Show log after scrïpt ends
    - Clique sur Execute pour que le fix fasse son boulot :-) Attends que le message Complete scrïpt execution apparaîsse et clique sur OK.
    Un rapport va s'afficher dans la fenetre du programme, copie et colle dans le bloc-notes, puis sauvegardes le, tu le posteras plus tard sur le forum.
    Clique Exit pour fermer le programme BFU.

    @+
    0
    1. chris
       
      salut ,

      excuses moi de t'embêter mais j'y connais pas grand chose je selectionne Driver , registry et file ou ?
      dans ton message ou ailleur ? merci de ta patience
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    salut

    tu sélectionne ceci

    Driver::
    int15.sys

    registry::

    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{787E5742-9E2A-43FA-8A2E-00B8733F908E}]

    File::
    C:\WINDOWS\ruwvxx.ini2
    C:\Acer\Empowering Technology\eRecovery\int15.sys



    @+
    0
    1. chrisetsylvain Messages postés 112 Statut Membre
       
      j'ai fait ce que tu m'as dis pour combofix mais pas de rapport ni sur le bureau ni sur le disque dur ????
      0
    2. chrisetsylvain Messages postés 112 Statut Membre
       
      j'ai fait une recherche et je l'ai trouvé :

      ComboFix 08-03-24.2 - christelle 2008-03-29 9:20:23.4 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.268 [GMT 1:00]
      Endroit: C:\Documents and Settings\christelle\Bureau\ComboFix.exe

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      ---- Previous Run -------
      .
      C:\Acer\Empowering Technology\eRecovery\int15.sys
      C:\WINDOWS\ruwvxx.ini2

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_INT15.SYS
      -------\Service_int15.sys
      -------\Legacy_INT15.SYS
      -------\Service_int15.sys


      ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-29 ))))))))))))))))))))))))))))))))))))
      .

      2008-03-28 16:59 . 2008-03-28 16:59 86 --a------ C:\WINDOWS\NeroDigital.ini
      2008-03-26 13:15 . 2003-12-05 13:51 1,318,912 --------- C:\WINDOWS\UNMRW.exe
      2008-03-26 13:15 . 2003-12-19 17:09 29,709 --------- C:\WINDOWS\UNMRW.cfg
      2008-03-26 13:15 . 2003-12-08 20:55 25,072 --------- C:\WINDOWS\system32\drivers\incdrm.sys
      2008-03-26 13:14 . 2003-12-04 15:53 1,318,912 --------- C:\WINDOWS\NuNinst.exe
      2008-03-26 13:14 . 2003-12-05 11:27 89,168 --------- C:\WINDOWS\system32\drivers\incdfs.sys
      2008-03-26 13:14 . 2003-12-19 17:09 46,185 --------- C:\WINDOWS\NuNinst.cfg
      2008-03-26 13:14 . 2003-12-05 11:27 28,592 --------- C:\WINDOWS\system32\drivers\incdpass.sys
      2008-03-26 13:14 . 2003-12-05 11:27 9,341 --------- C:\WINDOWS\system32\drivers\incdrec.sys
      2008-03-26 13:13 . 2008-03-26 13:13 <REP> d-------- C:\WINDOWS\InCD
      2008-03-26 13:12 . 2003-12-16 15:36 1,331,200 --------- C:\WINDOWS\UNNMP.exe
      2008-03-26 13:12 . 2003-12-19 17:09 50,779 --------- C:\WINDOWS\UNNMP.cfg
      2008-03-26 13:08 . 2001-07-09 11:50 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe
      2008-03-26 13:07 . 2003-12-11 13:34 1,318,912 --------- C:\WINDOWS\UNNeroVision.exe
      2008-03-26 13:07 . 2003-12-19 17:09 109,947 --------- C:\WINDOWS\UNNeroVision.cfg
      2008-03-26 13:06 . 2001-07-06 14:41 569,344 -ra------ C:\WINDOWS\system32\imagr5.dll
      2008-03-26 13:06 . 2001-07-06 12:44 544,768 -ra------ C:\WINDOWS\system32\imagx5.dll
      2008-03-26 13:06 . 2001-07-06 18:24 283,920 -ra------ C:\WINDOWS\system32\ImagXpr5.dll
      2008-03-26 13:06 . 2001-06-26 08:15 38,912 -ra------ C:\WINDOWS\system32\picn20.dll
      2008-03-26 11:46 . 2001-03-08 18:30 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
      2008-03-25 08:09 . 2008-03-26 07:33 <REP> d-------- C:\VundoFix Backups
      2008-03-16 12:16 . 2008-03-16 12:16 <REP> d-------- C:\LILIMATH
      2008-03-13 08:59 . 2008-03-13 08:59 <REP> d-------- C:\Program Files\PopCap Games
      2008-03-13 08:59 . 2008-03-13 08:59 51,355 --a------ C:\WINDOWS\system32\muzika.xm
      2008-03-09 19:58 . 2004-07-26 16:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
      2008-03-09 19:58 . 2004-07-26 16:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
      2008-03-09 19:58 . 2004-03-02 16:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
      2008-03-09 19:58 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
      2008-03-09 19:58 . 2004-03-02 16:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
      2008-03-07 14:03 . 2008-03-07 14:03 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
      2008-03-07 14:03 . 2008-03-07 14:03 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
      2008-03-07 13:40 . 2008-03-07 13:40 13,035 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
      2008-03-07 13:40 . 2008-03-07 13:40 1,358 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
      2008-03-07 13:39 . 2008-03-07 13:39 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
      2008-03-07 13:39 . 2008-03-07 13:39 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
      2008-03-07 13:39 . 2008-03-07 13:39 39,984 --a------ C:\WINDOWS\system32\drivers\symids.sys
      2008-03-07 13:39 . 2008-03-07 13:39 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
      2008-03-07 13:39 . 2008-03-07 13:39 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
      2008-03-07 13:39 . 2008-03-07 13:39 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
      2008-03-07 13:39 . 2008-03-07 13:39 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-03-28 16:04 --------- d-----w C:\Program Files\WinamaxPoker
      2008-03-26 20:01 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
      2008-03-26 18:53 --------- d-----w C:\Documents and Settings\christelle\Application Data\Ahead
      2008-03-26 12:15 --------- d-----w C:\Program Files\Ahead
      2008-03-26 12:06 --------- d-----w C:\Program Files\Fichiers communs\Ahead
      2008-03-26 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
      2008-03-25 06:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
      2008-03-24 15:03 --------- d-----w C:\Program Files\Java
      2008-03-22 21:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-03-22 18:25 --------- d-----w C:\Program Files\Hijackthis Version Française
      2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Toolbar
      2008-03-22 13:09 --------- d-----w C:\Program Files\Windows Live Favorites
      2008-03-22 13:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
      2008-03-22 13:08 --------- d-----w C:\Program Files\QuickTime
      2008-03-22 13:07 --------- d-----w C:\Program Files\Norton AntiVirus
      2008-03-22 13:06 --------- d-----w C:\Program Files\MSN Messenger
      2008-03-22 12:59 --------- d-----w C:\Program Files\Google
      2008-03-22 12:50 --------- d-----w C:\Program Files\a-squared Free
      2008-03-12 10:17 --------- d-----w C:\Program Files\RegistrySmart
      2008-03-06 20:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
      2008-03-06 20:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
      2008-03-06 20:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
      2008-03-05 12:42 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
      2008-03-05 12:42 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
      2008-03-05 12:42 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
      2008-02-17 17:44 691,545 ----a-w C:\WINDOWS\unins000.exe
      2008-02-10 14:14 --------- d-----w C:\Program Files\directx
      2008-02-10 14:13 --------- d-----w C:\Program Files\Commandos II
      2008-02-10 14:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-02-01 14:00 --------- d-----w C:\Program Files\Norton Security Scan
      2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
      2007-10-09 08:20 10 ----a-w C:\Program Files\.autoreg
      2007-07-04 11:14 4,704 ----a-w C:\Program Files\satsukidecodersettings.ini
      2007-07-04 11:13 680 ----a-w C:\Program Files\mpc2.reg
      2007-07-04 11:13 558 ----a-w C:\Program Files\mpc1.reg
      2007-07-04 11:13 32,422 ----a-w C:\Program Files\ffdssetts.reg
      2007-07-04 11:13 30,772 ----a-w C:\Program Files\ffdsvsetts.reg
      2007-07-04 11:13 3,476 ----a-w C:\Program Files\mpc7.reg
      2007-07-04 11:13 3,026 ----a-w C:\Program Files\mpc3.reg
      2007-07-04 11:13 236 ----a-w C:\Program Files\mpc4.reg
      2007-07-04 11:13 18,156 ----a-w C:\Program Files\mpc6.reg
      2007-07-04 11:13 16,290 ----a-w C:\Program Files\mpc5.reg
      2007-07-04 11:13 13,366 ----a-w C:\Program Files\ffdsasetts.reg
      2007-05-30 16:34 47,360 ----a-w C:\Documents and Settings\christelle\Application Data\pcouffin.sys
      2007-04-06 06:23 3,672,408 ----a-w C:\Documents and Settings\christelle\watch.exe
      2007-04-06 06:23 10,166,182 ----a-w C:\Documents and Settings\christelle\NBR6606FRA.exe
      2007-04-04 11:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
      2007-02-25 19:05 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6962.dat
      2007-02-25 18:49 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb1478.dat
      2007-02-25 17:13 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9358.dat
      2007-02-14 10:00 635,625 ----a-w C:\Documents and Settings\christelle\pays.zip
      2007-02-08 16:39 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb9169.dat
      2007-02-08 16:39 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb5724.dat
      2007-02-08 16:39 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6500.dat
      2007-02-04 12:49 374 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb6334.dat
      2007-02-04 12:46 18,432 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb41.dat
      2007-02-04 12:10 538 ----a-w C:\Documents and Settings\christelle\Application Data\internaldb8467.dat
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 06:00 15360]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 08:58 68856]
      "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.exe]
      "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
      "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
      "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 06:00 455168]
      "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15 45056]
      "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 06:00 59392]
      "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 12:48 425984]
      "LaunchApp"="Alaunch" []
      "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 06:00 208952]
      "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
      "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 17:00 397312]
      "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 15:07 114688]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
      "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
      "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 18:22 26248]
      "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43 286720]
      "WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2001-10-09 12:28 24576]
      "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-10-05 15:53 331830]
      "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-09-04 21:30 28738]
      "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
      "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
      "InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003-12-05 11:25 1237042]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 06:00 15360]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxwttq]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
      "C:\\WINDOWS\\system32\\ftp.exe"=
      "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
      "C:\\Program Files\\Outlook Express\\msimn.exe"=
      "C:\\WINDOWS\\system32\\rtcshare.exe"=
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
      "C:\\Program Files\\MSN Messenger\\livecall.exe"=
      "C:\\Program Files\\Shareaza\\Shareaza.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3587:TCP"= 3587:TCP:Groupement homologue Windows
      "3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
      "6346:TCP"= 6346:TCP:shareaza
      "6346:UDP"= 6346:UDP:shareaza

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 08:00]
      R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
      R2 MMIndexer;Media Manager Indexer;C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe [1997-07-14 23:00]
      S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 16:04]
      S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2004-08-05 06:00]
      S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" []

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

      *Newly Created Service* - INT15.SYS
      .
      Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
      "2008-03-17 22:00:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      "2007-02-12 12:38:00 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
      - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
      "2008-03-28 13:02:23 C:\WINDOWS\Tasks\Norton AntiVirus - Analyse système complète - christelle.job"
      0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour il faut faire le reste
    @+
    0
  8. chrisetsylvain Messages postés 112 Statut Membre
     
    c'est fait voilà le rapport bfu :

    BFU v1.11.0
    Windows XP SP2 (WinNT 5.01.2600 SP2)
    Script started at 09:53:50, on 2008-03-29

    Option Unload Explorer: Yes
    Success: ProcessKillByPID 3708
    Success: ProcessKill C:\WINDOWS\explorer.exe|1
    Warning: The following line has unexpanded aliases and will be skipped: # Winsoftware.bfu
    # lazzzy 20/09/2006
    # Ce script cible ErrorSafe / Winfixer / ErrorGuard / DriveCleaner / SystemDoctor / WinAntiVirusPro / WinAntiSpyware / SysProtect

    OptionUnloadShell

    # 1 - Processus

    ProcessKill \AdwareProtector.exe|1
    ProcessKill \ErrorGuard.exe|1
    ProcessKill \ERScw.exe|1
    ProcessKill C:\Program Files\WinAntiVirus Pro 2006\fat.exe|1
    ProcessKill \sd2006.exe|1
    ProcessKill \SDR6cw.exe|1
    ProcessKill \SDRmon.exe|1
    ProcessKill C:\Program Files\SystemDoctor 2006 Free\startmon.exe|1
    ProcessKill C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe|1
    ProcessKill C:\Program Files\systemdoctor 2006 free\updater.exe|1
    ProcessKill C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe|1
    ProcessKill C:\Program Files\DriveCleaner 2006 Free\udc6cw.exe|1
    ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe|1
    ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe|1
    ProcessKill C:\Program Files\WinAntiSpyware 2006 Scanner\updater.exe|1
    ProcessKill C:\Program Files\SystemDoctor 2006 Free\usdr6cw.exe|1
    ProcessKill C:\Program Files\SysProtect Free\USYP.exe|1
    ProcessKill C:\Program Files\WinAntiVirus Pro 2006\uwa6pcw.exe|1
    ProcessKill uwasffNT.exe|1
    ProcessKill \was6.exe|1
    ProcessKill \WinAV.exe|1
    ProcessKill \WinPG2005.exe|1

    # 2 - Services

    ServiceStop FWSvc
    ServiceDisable FWSvc
    ServiceDelete FWSvc

    # 3 - Registre

    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|AdwareProtector
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe Free
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafeFree
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1212
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect Free
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinPopupGuard 2005

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cmonitor
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|CompanionWizard
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6v_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6Y_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DriveCleaner 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorGuard
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERS_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERScw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fat.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Firewall
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRV_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRY_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MNI.UWFX5LP_0001_0614
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UAVIFR_0001_N105M2404
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERS_0001_NI57M1124
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N57M0112
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N68M1602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_LP
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N68M0602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91M2107
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91S2108
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_9999_N91S1912
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSY_0001_N68M0602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6PV_0001_N108M0207
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6P_5555_N122M0312
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6PV_0001_N122M1202
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGESV_0001_N122M0303
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ni.usyp
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0002_N91M1708
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0003_N91M0908
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PV_0001_N91M2107
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PY_0001_N73M0604
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N91M0510
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N96M0206
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N76M1904
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N91M2208
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6Y_0001_N91M2208
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_0802
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1412
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX6_0001_N68M2301
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|PAS_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|rtasks
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Salestart
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6V_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6Y_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|udc6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|UERScw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uga6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|usdr6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwa6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwas6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wa6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WA6PV_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Scanner
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirusPro2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirus Pro 2007
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat_reinstall
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|WinAntiSpyware 2006 Scanner

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\ErrorSafe\esPCheck.dll
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\common files\winantivirus pro 2006\wapchk.dll
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\WinAntiSpyware 2006 Scanner\uwasffNT.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\WINDOWS\system32\drivers\uwasfsd.sys

    RegDeleteKey HKCR\antiviruscom.avofficeprotect
    RegDeleteKey HKCR\antiviruscom.avofficeprotect.1
    RegDeleteKey HKCR\avexplorer.shellextension
    RegDeleteKey HKCR\avexplorer.shellextension.2
    RegDeleteKey HKCR\avexplorer.shellextension\curver
    RegDeleteKey HKCR\checkprod.checkproduct
    RegDeleteKey HKCR\CheckProduct2.CheckProduct
    RegDeleteKey HKCR\CheckProduct2.CheckProduct.1
    RegDeleteKey HKCR\ComCleanCor.AppCleane
    RegDeleteKey HKCR\ComCleanCor.AppCleane.1
    RegDeleteKey HKCR\ComCleanCor.CQuickScan
    RegDeleteKey HKCR\ComCleanCor.CQuickScan.1
    RegDeleteKey HKCR\ComCleanCor.FileCleane
    RegDeleteKey HKCR\ComCleanCor.InetCleane
    RegDeleteKey HKCR\ComCleanCor.InetCleane.1
    RegDeleteKey HKCR\ComCleanCor.RegCleane
    RegDeleteKey HKCR\ComCleanCor.RegCleane.1
    RegDeleteKey HKCR\ComCleanCor.SystemCleane
    RegDeleteKey HKCR\ComCleanCor.SystemCleane.1
    RegDeleteKey HKCR\ComCleanCore.FileClean.1
    RegDeleteKey HKCR\CompCleanCore.AppCleaner
    RegDeleteKey HKCR\CompCleanCore.AppCleaner.1
    RegDeleteKey HKCR\CompCleanCore.CCQuickScan
    RegDeleteKey HKCR\CompCleanCore.CCQuickScan.1
    RegDeleteKey HKCR\CompCleanCore.FileCleaner
    RegDeleteKey HKCR\CompCleanCore.FileCleaner.1
    RegDeleteKey HKCR\CompCleanCore.InetCleaner
    RegDeleteKey HKCR\CompCleanCore.InetCleaner.1
    RegDeleteKey HKCR\CompCleanCore.RegCleaner
    RegDeleteKey HKCR\CompCleanCore.RegCleaner.1
    RegDeleteKey HKCR\CompCleanCore.SystemCleaner
    RegDeleteKey HKCR\CompCleanCore.SystemCleaner.1
    RegDeleteKey HKCR\df_fixer.Fixer
    RegDeleteKey HKCR\df_fixer.Fixer.1
    RegDeleteKey HKCR\df_proxy.DriverManipulate
    RegDeleteKey HKCR\df_proxy.DriverManipulate.1
    RegDeleteKey HKCR\df_fix.Fix
    RegDeleteKey HKCR\df_fix.Fix.1
    RegDeleteKey HKCR\df_prx.DriverManipulat
    RegDeleteKey HKCR\df_prx.DriverManipulat.1
    RegDeleteKey HKCR\escompcleancore.esappcleaner
    RegDeleteKey HKCR\escompcleancore.esappcleaner.1
    RegDeleteKey HKCR\escompcleancore.esccquickscan
    RegDeleteKey HKCR\escompcleancore.esccquickscan.1
    RegDeleteKey HKCR\escompcleancore.esfilecleaner
    RegDeleteKey HKCR\escompcleancore.esfilecleaner.1
    RegDeleteKey HKCR\escompcleancore.esinetcleaner
    RegDeleteKey HKCR\escompcleancore.esinetcleaner.1
    RegDeleteKey HKCR\escompcleancore.esregcleaner
    RegDeleteKey HKCR\escompcleancore.esregcleaner.1
    RegDeleteKey HKCR\escompcleancore.essystemcleaner
    RegDeleteKey HKCR\escompcleancore.essystemcleaner.1
    RegDeleteKey HKCR\esdf_fixer.esfixer
    RegDeleteKey HKCR\esdf_fixer.esfixer.1
    RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate
    RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate.1
    RegDeleteKey HKCR\esffwraper.esffenginwraper
    RegDeleteKey HKCR\esffwraper.esffenginwraper.1
    RegDeleteKey HKCR\esfixcore.esmmfixcore
    RegDeleteKey HKCR\esfixcore.esmmfixcore.1
    RegDeleteKey HKCR\esmmfixctrl.escofixengine
    RegDeleteKey HKCR\esmmfixctrl.escofixengine.1
    RegDeleteKey HKCR\esspchck.esspchck
    RegDeleteKey HKCR\esspchck.esspchck.1
    RegDeleteKey HKCR\esspcheck.esspcheck
    RegDeleteKey HKCR\esspcheck.esspcheck.1
    RegDeleteKey HKCR\FFCom.FlFixer
    RegDeleteKey HKCR\FFWraper.FFEnginWraper
    RegDeleteKey HKCR\FFWrap.FEnginWrape
    RegDeleteKey HKCR\FFWrap.FEnginWrape.1
    RegDeleteKey HKCR\FFWraper.FFEnginWraper.1
    RegDeleteKey HKCR\FFxr_21.FFixr21
    RegDeleteKey HKCR\FixCor.MMFxCor
    RegDeleteKey HKCR\FixCor.MMFxCor.1
    RegDeleteKey HKCR\FixCore.MMFixCore
    RegDeleteKey HKCR\FixCore.MMFixCore.1
    RegDeleteKey HKCR\FlFxr3.FlFixer3
    RegDeleteKey HKCR\flfxr5.flfixer5
    RegDeleteKey HKCR\FlFxr15.FlFixer15
    RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r
    RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r.1
    RegDeleteKey HKCR\FWraper.FFEnginWraper
    RegDeleteKey HKCR\FWraper.FFEnginWraper.1
    RegDeleteKey HKCR\FxCor_e.MMFixCor_e.1
    RegDeleteKey HKCR\FxCor_e.MMFixCor_e
    RegDeleteKey HKCR\FxCore.MMFixCore
    RegDeleteKey HKCR\FxCore.MMFixCore.1
    RegDeleteKey HKCR\iefwbho.iefw
    RegDeleteKey HKCR\iefwbho.iefw.2
    RegDeleteKey HKCR\Install.Install
    RegDeleteKey HKCR\Install.Install.1
    RegDeleteKey HKCR\MMFixCtrl.CoFixEngine
    RegDeleteKey HKCR\MMFixCtrl.CoFixEngine.1
    RegDeleteKey HKCR\MMFx.CoFxEngin
    RegDeleteKey HKCR\MMFx.CoFxEngin.1
    RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e
    RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e.1
    RegDeleteKey HKCR\systemdoctor.free
    RegDeleteKey HKCR\UWFX6PCheck.UWFX6PCheck.2
    RegDeleteKey HKCR\UWFXCheck.UWFXCheck
    RegDeleteKey HKCR\UWFXCheck.UWFXCheck.1
    RegDeleteKey HKCR\wap6.pcheck
    RegDeleteKey HKCR\wap6.pcheck.1
    RegDeleteKey HKCR\winpgintegrator.ieintegrator
    RegDeleteKey HKCR\winpgintegrator.ieintegrator.1

    RegDeleteKey HKCR\AppID\{25A3C995-10C8-474B-A167-99460AB4AB2B}
    RegDeleteKey HKCR\AppID\{287A2BAD-6590-4EFF-9BBC-494385664A73}
    RegDeleteKey HKCR\AppID\{290B5B73-4963-4BA1-9D2D-07CB566CB7FA}
    RegDeleteKey HKCR\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9}
    RegDeleteKey HKCR\AppID\{3C132D19-6103-4fc3-8326-34E13EE9E2C0}
    RegDeleteKey HKCR\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
    RegDeleteKey HKCR\AppID\{8C65AEF6-E413-4314-815B-82717A3F1603}
    RegDeleteKey HKCR\AppID\{AAB0BA34-6D48-425f-B4B4-98F158CB61F1}
    RegDeleteKey HKCR\AppID\{DED71DE6-0575-4556-8311-A506B116A1A9}
    RegDeleteKey HKCR\AppID\{E8928E69-C050-42A9-8884-94DE85E888A2}
    RegDeleteKey HKCR\AppID\{E11FF09D-39AF-4613-86AD-F3217E576571}
    RegDeleteKey HKCR\AppID\CheckProduct2.DLL
    RegDeleteKey HKCR\AppID\compcln.dll
    RegDeleteKey HKCR\AppID\compclr.dll
    RegDeleteKey HKCR\AppID\FFWrapr.DLL
    RegDeleteKey HKCR\AppID\FFWraper.DLL
    RegDeleteKey HKCR\AppID\FixCore.DLL
    RegDeleteKey HKCR\AppID\FxCr.DLL
    RegDeleteKey HKCR\AppID\MFix.DLL
    RegDeleteKey HKCR\AppID\MMFixCtrl.DLL
    RegDeleteKey HKCR\AppID\winpgi.dll appid

    RegDeleteKey HKCR\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKCR\CLSID\{0ba379c6-0efd-4a28-932c-d20469052fd9}
    RegDeleteKey HKCR\CLSID\{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
    RegDeleteKey HKCR\CLSID\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
    RegDeleteKey HKCR\CLSID\{151a44b0-fc2d-4a02-bbbc-6b372f2f659c}
    RegDeleteKey HKCR\CLSID\{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
    RegDeleteKey HKCR\CLSID\{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
    RegDeleteKey HKCR\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
    RegDeleteKey HKCR\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
    RegDeleteKey HKCR\CLSID\{205FF73B-CA67-11D5-99DD-444553540006}
    RegDeleteKey HKCR\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
    RegDeleteKey HKCR\CLSID\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
    RegDeleteKey HKCR\CLSID\{356af2e9-8874-4c60-a3d8-0cb516c9e747}
    RegDeleteKey HKCR\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
    RegDeleteKey HKCR\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
    RegDeleteKey HKCR\CLSID\{5284ac2a-ef00-4750-9b82-b5b907d26536}
    RegDeleteKey HKCR\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
    RegDeleteKey HKCR\CLSID\{53ABACCB-434C-4756-A02B-8C2A3F29FB7D}
    RegDeleteKey HKCR\CLSID\{5A1C8180-2A52-470c-938C-BFB4E63AA32D}
    RegDeleteKey HKCR\CLSID\{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
    RegDeleteKey HKCR\CLSID\{647b8364-79e0-48e2-a4ca-233abada0c2d}
    RegDeleteKey HKCR\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
    RegDeleteKey HKCR\CLSID\{6F85DDE5-A2DE-4217-A05D-0A7CD3C04DC2}
    RegDeleteKey HKCR\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d}
    RegDeleteKey HKCR\CLSID\{72D597C4-2312-4116-BED4-4F9A2B2F710E}
    RegDeleteKey HKCR\CLSID\{77ca442a-0c72-492b-804a-82611e558142}
    RegDeleteKey HKCR\CLSID\{7e73c9db-69fb-4580-8e8e-194b34a2306c}
    RegDeleteKey HKCR\CLSID\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
    RegDeleteKey HKCR\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
    RegDeleteKey HKCR\CLSID\{861D5757-3A7E-4c46-966E-8CD53A0D0013}
    RegDeleteKey HKCR\CLSID\{8E3A1531-F462-4628-ADD8-D32984637641}
    RegDeleteKey HKCR\CLSID\{965a8d33-ae18-4c17-8011-fe42d81e0758}
    RegDeleteKey HKCR\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
    RegDeleteKey HKCR\CLSID\{9e87077c-380c-407d-8dab-eedad95c0a5d}
    RegDeleteKey HKCR\CLSID\{9F3D2A3C-D537-482b-A91B-44EE29F09C4B}
    RegDeleteKey HKCR\CLSID\{A99498D2-56E1-4e27-AC88-2328C6A87C7C}
    RegDeleteKey HKCR\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
    RegDeleteKey HKCR\CLSID\{ABC72615-4FB0-4689-AED9-AA6B89CEBC2C}
    RegDeleteKey HKCR\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
    RegDeleteKey HKCR\CLSID\{B296F12B-48A9-45fb-A860-4B98707B47AE}
    RegDeleteKey HKCR\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
    RegDeleteKey HKCR\CLSID\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
    RegDeleteKey HKCR\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
    RegDeleteKey HKCR\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
    RegDeleteKey HKCR\CLSID\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
    RegDeleteKey HKCR\CLSID\{B8CA1E6C-87E2-4435-9E56-8B791EC459D8}
    RegDeleteKey HKCR\CLSID\{c033567c-68fe-419b-bcc4-135db7faf8eb}
    RegDeleteKey HKCR\CLSID\{C08FA317-C152-4fea-AC0B-2EA68D2B1C84}
    RegDeleteKey HKCR\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
    RegDeleteKey HKCR\CLSID\{C427B3E3-28DC-4001-9590-D99B6776119B}
    RegDeleteKey HKCR\CLSID\{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
    RegDeleteKey HKCR\CLSID\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
    RegDeleteKey HKCR\CLSID\{ccaabcdd-7c16-4215-b12e-150bfb994cf0}
    RegDeleteKey HKCR\CLSID\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
    RegDeleteKey HKCR\CLSID\{e73e3959-fb15-44d7-acb9-3a75377006fc}
    RegDeleteKey HKCR\CLSID\{EAB5DB02-08F5-4e7d-81F9-75B9462FAAE3}
    RegDeleteKey HKCR\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
    RegDeleteKey HKCR\CLSID\{F0ED6398-E5F8-4ef8-BAB9-FE9BBCE7EF3E}
    RegDeleteKey HKCR\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKCR\CLSID\{f63e3b76-f82f-46eb-851c-8c0a221686bb}
    RegDeleteKey HKCR\CLSID\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

    RegDeleteKey HKCR\Interface\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKCR\Interface\{02946fd1-2d99-46e6-a790-3a089714edd9}
    RegDeleteKey HKCR\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442}
    RegDeleteKey HKCR\Interface\{1CE1C25B-F8B4-4974-99D2-5D4AE96B9900}
    RegDeleteKey HKCR\Interface\{35096C29-3507-4ABE-B6D8-C7CC881BE020}
    RegDeleteKey HKCR\Interface\{38F743A2-210F-49DE-9B79-DCD501CED284}
    RegDeleteKey HKCR\Interface\{3EEC290D-FC13-4C83-803D-4802651EEB61}
    RegDeleteKey HKCR\Interface\{41A5BBF6-3C9D-4CF9-9A99-32DD37CC290B}
    RegDeleteKey HKCR\Interface\{4E4F38D9-8736-41AE-B192-E829AE194398}
    RegDeleteKey HKCR\Interface\{4F79D1C5-24F9-4E59-8022-604D4B41D5CA}
    RegDeleteKey HKCR\Interface\{66484903-09F4-4330-927D-1F6C214221AC}
    RegDeleteKey HKCR\Interface\{7FA14AD6-D8E5-465F-9BD1-A37E26C1A74F}
    RegDeleteKey HKCR\Interface\{9E984934-CD94-4763-9DBC-618E483D4B7F}
    RegDeleteKey HKCR\Interface\{B115BD8E-B008-46F4-B8B6-3405EB325C3C}
    RegDeleteKey HKCR\Interface\{B9DFCF32-B679-4CAD-B7FC-518A48CE3922}
    RegDeleteKey HKCR\Interface\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
    RegDeleteKey HKCR\Interface\{CBEEF194-EBC5-4758-9B51-AC34FC135E70}
    RegDeleteKey HKCR\Interface\{CD3604CC-2B95-43EE-AFC9-E7444C21BE1C}
    RegDeleteKey HKCR\Interface\{D21040FE-0A57-4FAB-8ED2-F0E653E55809}
    RegDeleteKey HKCR\Interface\{D7A2488E-53E4-4EDD-AEAA-F24778BEB100}
    RegDeleteKey HKCR\Interface\{D7A6DF8D-B6CF-4C27-8E99-ECA2CE370EA7}
    RegDeleteKey HKCR\Interface\{e18b69d0-7e9e-4c6e-bdd8-879a1fff7123}
    RegDeleteKey HKCR\Interface\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKCR\Interface\{F6C1582E-B11C-4724-B8F6-240457EF1D2A}
    RegDeleteKey HKCR\Interface\{FB787D5E-0C7C-4BAB-B45D-20325FB886DB}
    RegDeleteKey HKCR\Interface\{24F3E817-2C07-4CB5-975D-F23FCFAEDE51}
    RegDeleteKey HKCR\Interface\{3BB63444-FD94-4C31-9D6F-0DA76CB11D70}
    RegDeleteKey HKCR\Interface\{3C2656F4-8601-42B6-BDC3-DEC901E21C80}
    RegDeleteKey HKCR\Interface\{471D3AEF-F18C-4626-A7DB-320732ACC763}
    RegDeleteKey HKCR\Interface\{490E59CC-F6D5-4987-BBC8-E1A6D599C3F8}
    RegDeleteKey HKCR\Interface\{68A7506D-DF03-4DF0-BE96-02BCB918EA7D}
    RegDeleteKey HKCR\Interface\{74ECF6F4-62C5-48BA-945E-B20A97239A5E}
    RegDeleteKey HKCR\Interface\{7A66E632-E262-4986-A936-CC636282F138}
    RegDeleteKey HKCR\Interface\{7D9DFDB3-5135-4279-B365-3CEEA4AC1EAC}
    RegDeleteKey HKCR\Interface\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
    RegDeleteKey HKCR\Interface\{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
    RegDeleteKey HKCR\Interface\{81A7D75C-9768-41C3-AE0F-8B108D802B62}
    RegDeleteKey HKCR\Interface\{86786BEC-544D-473F-8D93-8E7AC0685361}
    RegDeleteKey HKCR\Interface\{92B92664-32D6-4FCE-B2CE-C8519BAEFC4E}
    RegDeleteKey HKCR\Interface\{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
    RegDeleteKey HKCR\Interface\{B0725565-2694-43EC-B1AB-0245762C9860}
    RegDeleteKey HKCR\Interface\{B26CA1F6-2D46-49AE-9897-9C5B7CCAB9FB}
    RegDeleteKey HKCR\Interface\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
    RegDeleteKey HKCR\Interface\{CADCB2CC-0B7E-45B1-A689-A0AD9CE5932D}
    RegDeleteKey HKCR\Interface\{D3390AE7-6F1D-464F-8921-AF9A85EED316}
    RegDeleteKey HKCR\Interface\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
    RegDeleteKey HKCR\Interface\{DB064061-95F1-4BAF-BEC9-F70792E01094}
    RegDeleteKey HKCR\Interface\{F3067DE7-3DBA-4DF8-9FA0-6B0200BAA324}
    RegDeleteKey HKCR\Interface\{f5ac8b35-5b15-4e8f-8046-43858973b495}
    RegDeleteKey HKCR\Interface\{FE899520-E9F9-4CD9-AABB-E9074815CF50}

    RegDeleteKey HKCR\TypeLib\{04392304-5221-4022-9300-be4128fb25b2}
    RegDeleteKey HKCR\TypeLib\{0E9F6AC0-A21A-4591-910F-E2C6F3CA094C}
    RegDeleteKey HKCR\TypeLib\{1234890a-5e6e-4867-8136-ca6f1456b235}
    RegDeleteKey HKCR\TypeLib\{1b197c22-561f-455f-8511-35b1a45c5c9f}
    RegDeleteKey HKCR\TypeLib\{17E55F3A-20AB-4668-A75F-DC96377AE16C}
    RegDeleteKey HKCR\TypeLib\(205FF72E-CA67-11D5-99DD-444553540006)
    RegDeleteKey HKCR\TypeLib\{248FDD41-4E0A-4138-9086-6CF5D6FA8179}
    RegDeleteKey HKCR\TypeLib\{25BAE2A9-DF54-4927-AF6F-9963146D11D8}
    RegDeleteKey HKCR\TypeLib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276}
    RegDeleteKey HKCR\TypeLib\{30ED49A5-CA6C-4918-B5F3-5E6818C91D8B}
    RegDeleteKey HKCR\TypeLib\{367a86a5-d048-4785-86be-4e2706aafdd9}
    RegDeleteKey HKCR\TypeLib\{371EFE75-C183-4D0C-B8CD-2DFAFEEB34D7}
    RegDeleteKey HKCR\TypeLib\{49f9ffb5-514d-4b69-b31d-2ae5a7d30ae6}
    RegDeleteKey HKCR\TypeLib\{4DCEEA42-794D-4855-9ECC-20DCF5F4FEA7}
    RegDeleteKey HKCR\TypeLib\{5F638503-4F2E-48F8-9210-9865AF4AD020}
    RegDeleteKey HKCR\TypeLib\{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
    RegDeleteKey HKCR\TypeLib\{692ca430-32c8-470d-ba1f-7e15e21e7043}
    RegDeleteKey HKCR\TypeLib\{6A077841-5016-42C8-92C8-F2D6B865BCD1}
    RegDeleteKey HKCR\TypeLib\{6bd7e052-306e-497a-ad23-601bc6bfc305}
    RegDeleteKey HKCR\TypeLib\{6F9DB588-66C5-4904-A2C7-423961358E8C}
    RegDeleteKey HKCR\TypeLib\{732b6533-7f78-4c47-9c01-2979ba0829b9}
    RegDeleteKey HKCR\TypeLib\{77dc6558-60e0-4644-a3df-b31f29d113bd}
    RegDeleteKey HKCR\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
    RegDeleteKey HKCR\TypeLib\{8D67C4E4-AAD6-46A1-812F-D7D21BBB4624}
    RegDeleteKey HKCR\TypeLib\{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
    RegDeleteKey HKCR\TypeLib\{a73973ab-95a6-4abe-a046-de3bab2be448}
    RegDeleteKey HKCR\TypeLib\{AD70AC89-F460-4E7E-B5A5-7EAF7E207736}
    RegDeleteKey HKCR\TypeLib\{B6625280-8CD8-4632-97C0-83CEC12A49A3}
    RegDeleteKey HKCR\TypeLib\{D49C1A5F-26CF-482E-81EE-1D4C9B057BD2}
    RegDeleteKey HKCR\TypeLib\{F458ADAE-D53B-4859-B99F-9FA127791278}
    RegDeleteKey HKCR\TypeLib\{FC76A5B8-DB35-4F3E-8B9A-BF0EEA098D64}

    RegDeleteKey HKCU\Software\ErrorGuard
    RegDeleteKey HKCU\Software\errorsafe
    RegDeleteKey HKCU\Software\error safe free
    RegDeleteKey HKCU\Software\sysprotect free
    RegDeleteKey HKCU\Software\SystemDoctor 2006 Free
    RegDeleteKey HKCU\Software\WinAntiSpyware 2006 Scanner
    RegDeleteKey HKCU\Software\WinAntiVirus Pro 2006
    RegDeleteKey HKCU\Software\WinFixer 2005
    RegDeleteKey HKCU\Software\WinSoftware

    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{205ff73b-ca67-11d5-99dd-444553540006}
    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}

    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SystemDoctor 2006 Unregistered

    RegDeleteKey HKLM\Software\DriveCleaner 2006 Free
    RegDeleteKey HKLM\Software\ErrorSafe
    RegDeleteKey HKLM\Software\Error Safe Free
    RegDeleteKey HKLM\Software\sysprotect
    RegDeleteKey HKLM\Software\SystemDoctor 2006 Free
    RegDeleteKey HKLM\Software\WinAntiSpyware 2006 Scanner
    RegDeleteKey HKLM\Software\winantivirus pro 2006
    RegDeleteKey HKLM\Software\WinSoftware

    RegDeleteKey HKLM\Software\Classes\checkprod.checkproduct
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.AppCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner\CLSID
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner.1
    RegDeleteKey HKLM\Software\Classes\df_fixr.Fixer
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer
    RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer.1
    RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate
    RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate.1
    RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper
    RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper.1
    RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore
    RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore.1
    RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine
    RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine.1
    RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck
    RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck.1
    RegDeleteKey HKLM\Software\Classes\FFWraper.FFEnginWrapr
    RegDeleteKey HKLM\Software\Classes\FixCor.MMFixCore
    RegDeleteKey HKLM\Software\Classes\FlFxr5.FlFixer5
    RegDeleteKey HKLM\Software\Classes\FlFxr10.FlFixer10
    RegDeleteKey HKLM\Software\Classes\MMFixCtrl.CoFixEngin2
    RegDeleteKey HKLM\Software\Classes\SystemDoctor.Free
    RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk
    RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk.1
    RegDeleteKey HKLM\Software\Classes\UDCShell
    RegDeleteKey HKLM\Software\Classes\UWAS6.UWAS6
    RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier
    RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier.1
    RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook
    RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook.1
    RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu
    RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu.1
    RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier
    RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier.1
    RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu
    RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu.1
    RegDeleteKey HKLM\Software\Classes\WASPChk.WASPChk

    RegDeleteKey HKLM\Software\Classes\*\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\AppID\{1C02CE6B-CC12-4ea1-B2D8-113F611F25C2}
    RegDeleteKey HKLM\Software\Classes\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
    RegDeleteKey HKLM\Software\Classes\AppID\{8A1E94DA-725D-4f64-B110-DB3F73ADB6F7}
    RegDeleteKey HKLM\Software\Classes\AppID\{E7E155EE-EEF2-46af-99B7-65F1269DC3CF}
    RegDeleteKey HKLM\Software\Classes\AppID\{EE10A303-0C60-4acb-A033-95A790FA4DCD}
    RegDeleteKey HKLM\Software\Classes\AppID\checkproduct2_1.dll

    RegDeleteKey HKLM\Software\Classes\CLSID\{_CLSID_WAShellExecuteCheck}
    RegDeleteKey HKLM\Software\Classes\CLSID\{05324ED1-05C0-4e3a-A34F-98BFC64426F5}
    RegDeleteKey HKLM\Software\Classes\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKLM\Software\Classes\CLSID\{0D7DE254-2FBD-4C09-9077-3DC4A2DEBE9D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1230649B-B980-44A5-B259-9B09EBEA6331}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1236DE55-EDED-4675-AF10-BA15EDDB4D7A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{184B0A26-4C9C-4757-ABF5-4B6AF71F9A45}
    RegDeleteKey HKLM\Software\Classes\CLSID\{18A41B20-E519-47a1-B545-FFC200730E9B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{22024DC7-D190-44ec-9D49-AEE5F244A466}
    RegDeleteKey HKLM\Software\Classes\CLSID\{250D1063-5414-4fb0-86D5-AABB7A5D7DA7}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2B334C22-40CA-438f-913A-61A8105C4CCD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2BF3C5AD-F9EC-49d8-8568-D7DFFC77108B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{43DB73EB-4C90-4418-B6AD-10DB22016908}
    RegDeleteKey HKLM\Software\Classes\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
    RegDeleteKey HKLM\Software\Classes\CLSID\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{4F4E2384-42AD-4fe4-B966-B6D50C7BF90A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{5284AC2A-EF00-4750-9B82-B5B907D26536}
    RegDeleteKey HKLM\Software\Classes\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
    RegDeleteKey HKLM\Software\Classes\CLSID\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{5D178DBE-C867-417f-8A4E-D5DEFA4CD4E7}
    RegDeleteKey HKLM\Software\Classes\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{6C8416A2-2408-4f4d-8D26-EC9A07E8DC98}
    RegDeleteKey HKLM\Software\Classes\CLSID\{7D435027-F646-4bf9-B2C5-0EF4940D5CA2}
    RegDeleteKey HKLM\Software\Classes\CLSID\{7EC618F2-C506-4221-9F56-792B92BF762E}
    RegDeleteKey HKLM\Software\Classes\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
    RegDeleteKey HKLM\Software\Classes\CLSID\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9C102B96-4845-4756-991E-4F9294965536}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9CB12DAD-32C7-4f34-9758-C9FDD26D4D22}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B11}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B22}
    RegDeleteKey HKLM\Software\Classes\CLSID\{AE84FF0C-BABD-4D91-92A1-AF75D2D02E6D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
    RegDeleteKey HKLM\Software\Classes\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
    RegDeleteKey HKLM\Software\Classes\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C3E2988E-1433-469d-BFC1-4080D131FE1A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C4C4786C-9861-46d2-BB63-AC782AB07046}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C833A552-F5AF-4a7b-87B3-6EBDE0DB3B43}
    RegDeleteKey HKLM\Software\Classes\CLSID\{CF080118-CDA5-429d-A8BD-EC7ECA74663F}
    RegDeleteKey HKLM\Software\Classes\CLSID\{D3377825-230D-4a12-805C-132557FA1A8B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{D7136B99-FC27-4DC1-8497-5444D49B426A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{DD45A464-7763-43EE-A756-5F2C93B0CF5E}
    RegDeleteKey HKLM\Software\Classes\CLSID\{E4A3F67D-5237-43fa-B3F2-41C37C1204B9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{E78EA05B-B6A7-4dc4-879D-444DCD224CB4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{EDF78E1B-31A2-4c6e-AD40-0AFCD0D55263}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
    RegDeleteKey HKLM\Software\Classes\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKLM\Software\Classes\CLSID\{F5AB293C-2E21-4441-9AD8-B3646EB26DF5}
    RegDeleteKey HKLM\Software\Classes\CLSID\{FDA9BFC7-4ECD-43a0-AC1E-2E7DDE0C81B0}
    RegDeleteKey HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\{7EC618F2-C506-4221-9F56-792B92BF762E}

    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerUWAS
    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerWAS
    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerUWAS
    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerWAS
    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9}
    RegDeleteKey HKLM\Software\Classes\Interface\{0D146B7F-FA35-465D-B716-BCBC1F9A92D3}
    RegDeleteKey HKLM\Software\Classes\Interface\{12813770-461E-4A9F-8C5B-C227A8E9FBE8}
    RegDeleteKey HKLM\Software\Classes\Interface\{1562D24E-F5BF-4BB4-AF4C-BBB610B62638}
    RegDeleteKey HKLM\Software\Classes\Interface\{1BEA1806-F5C7-4696-B0A0-26CFD6A958DD}
    RegDeleteKey HKLM\Software\Classes\Interface\{258E07A2-FF65-493B-B6BD-421A1F2992A3}
    RegDeleteKey HKLM\Software\Classes\Interface\{2A1647E8-3EC2-49FE-B632-E12D765FA0CC}
    RegDeleteKey HKLM\Software\Classes\Interface\{2DECFCC9-D910-4BAC-94B8-FC006827A60F}
    RegDeleteKey HKLM\Software\Classes\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
    RegDeleteKey HKLM\Software\Classes\Interface\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
    RegDeleteKey HKLM\Software\Classes\Interface\{4B6A7638-0999-4924-93B7-C5738E1BAEE1}
    RegDeleteKey HKLM\Software\Classes\Interface\{5585C185-B318-4072-A00D-8385F443AE07}
    RegDeleteKey HKLM\Software\Classes\Interface\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
    RegDeleteKey HKLM\Software\Classes\Interface\{622423BD-B825-4989-BA65-86D0B990D328}
    RegDeleteKey HKLM\Software\Classes\Interface\{6813BFFD-BE81-4613-B4E6-AA7ED0DA8659}
    RegDeleteKey HKLM\Software\Classes\Interface\{7516C86C-2F3D-4724-BD4E-1608F1BDAE12}
    RegDeleteKey HKLM\Software\Classes\Interface\{7CA36000-3320-49D1-BAD1-4C5169D4084A}
    RegDeleteKey HKLM\Software\Classes\Interface\{7E7A1949-5C0C-45F3-A106-34FE038493EF}
    RegDeleteKey HKLM\Software\Classes\Interface\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
    RegDeleteKey HKLM\Software\Classes\Interface\{8E0A02C1-974F-4379-BFD3-69FFB9E0659D}
    RegDeleteKey HKLM\Software\Classes\Interface\{9793B356-4337-44AC-9A22-DF6A7930602C}
    RegDeleteKey HKLM\Software\Classes\Interface\{A1DDDD67-64B2-4CAB-BE0B-E34F3F12AED0}
    RegDeleteKey HKLM\Software\Classes\Interface\{A22FBA1E-CAAF-4E45-8EFF-4A821AF03E69}
    RegDeleteKey HKLM\Software\Classes\Interface\{A56B6D30-FDE0-42A9-BE6B-18B5D3F2F519}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95411}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95422}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42611}
    RegDeleteKey HKLM\Software\Classes\Interface\{A0E2E5AB-C02F-489B-BD7B-58C329F774F3}
    RegDeleteKey HKLM\Software\Classes\Interface\{A6E398B2-A288-4D76-B0D0-8F153D14B66E}
    RegDeleteKey HKLM\Software\Classes\Interface\{A92616B1-2E82-4052-B579-0A40C2304380}
    RegDeleteKey HKLM\Software\Classes\Interface\{B22EE952-9A58-4495-AE78-C0146FA1A3C7}
    RegDeleteKey HKLM\Software\Classes\Interface\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
    RegDeleteKey HKLM\Software\Classes\Interface\{C3896A1E-8ECD-490B-8A1C-39FE9F7D64A1}
    RegDeleteKey HKLM\Software\Classes\Interface\{C88B2356-A6FE-41EC-B0FB-41F2C82C867E}
    RegDeleteKey HKLM\Software\Classes\Interface\{CF5C9FCE-C963-49E5-A3A4-0A81FFFE1E55}
    RegDeleteKey HKLM\Software\Classes\Interface\{D090E12D-B79C-4B82-A76C-0E3BBE73C9EF}
    RegDeleteKey HKLM\Software\Classes\Interface\{D7136B99-FC27-4DC1-8497-5444D49B426A}
    RegDeleteKey HKLM\Software\Classes\Interface\{D80A56D7-451C-41CF-9A74-1447E0887B97}
    RegDeleteKey HKLM\Software\Classes\Interface\{DE3C77B8-7378-4A4C-B6F8-4A008B4A6009}
    RegDeleteKey HKLM\Software\Classes\Interface\{E0110779-5F79-4685-9C96-9D99EFD30CA2}
    RegDeleteKey HKLM\Software\Classes\Interface\{E7CCBD19-2EEA-4B6A-B9BE-E8A68613809C}
    RegDeleteKey HKLM\Software\Classes\Interface\{E95F8133-A554-4C0C-9B9A-EEEE3B82CEDE}
    RegDeleteKey HKLM\Software\Classes\Interface\{EA0F107F-2BF6-44A0-96C4-A99B74AFBC4A}
    RegDeleteKey HKLM\Software\Classes\Interface\{F18701B3-185D-42FD-A55E-F47FDAC8F362}
    RegDeleteKey HKLM\Software\Classes\Interface\{F709F572-86F5-47C8-AFCF-3CEBC468FADB}
    RegDeleteKey HKLM\Software\Classes\Interface\{F97E5B38-4887-444A-86F5-91C18331500B}
    RegDeleteKey HKLM\Software\Classes\Interface\{F9AC5167-2C13-4607-B924-81C1C2251C84}
    RegDeleteKey HKLM\Software\Classes\Interface\{FB752175-36D8-4792-9302CFB8018C0DEC}

    RegDeleteKey HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\SYSTEM\ControlSet003\Services\wasfsd

    RegDeleteKey HKLM\Software\Classes\TypeLib\{03A78DBD-AA12-4DB4-AB2C-564460D385DC}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{09AF1CF9-825C-4017-A7DC-088C68770F31}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{0A89FF7F-1A12-42D9-ACCB-4217112DC7E0}
    RegDeleteKey HKLM\software\classes\typelib\{1234890a-5e6e-4867-8136-ca6f1456b235}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{12398A44-7DFC-4C46-BD8F-41259D169A0D}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{16DEEE6B-AEFC-4BA6-9F32-57BBE6783A7C}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{21C724D0-B91A-4F35-99E7-55D325F00B20}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{223CEDCA-738B-4C4D-B8AE-C68B68C90A4A}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{5940CA88-8F1A-4A74-89E4-B3407E5E7348}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{61C1FC79-7120-4824-A563-D4D11D80BAFB}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{68BC55E9-4D3E-4C89-89AC-7559763C98B8}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{692CA430-32C8-470D-BA1F-7E15E21E7043}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{8ECC09E1-634B-42AC-8BE7-E6EDBB53C90E}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{A8C9AD38-7708-4BEB-A20C-B79614B4F120}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37411}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37422}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{B869788C-35DF-4104-BACB-8FDB83AFFFFD}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{BD9421BB-9F96-4272-802F-49BEC746056E}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{F874A0AE-66E8-426B-A3F5-6BA6958DCDBA}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{FB42F450-C8B1-4799-99F1-87FA9CA92AB9}

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\errorguard.exe

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{205ff73b-ca67-11d5-99dd-444553540006}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8C65AEF6-E413-4314-815B-82717A3F1603}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3B4C621-6024-410B-9F0F-22CBD6981F5E}

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Error Guard
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ERS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ersu_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UDC6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6V_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\usyp_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWFX_5_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWinFX6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\wa6p_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WAS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WFX5_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAntiSpyware 2006 Scanner_is1

    RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sscan.sys
    RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sscan.sys

    RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\FOPN
    RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\uwasfsd
    RegDeleteKey HKLM\SYSTEM\ControlSet002\Services\FOPN

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\df_km.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ersd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sscan.sys

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\df_kmd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ersd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sscan.sys

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ERSD
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\enum\root\legacy_erssdd

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\df_kmd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\ersd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\erssdd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FOPN
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\uwasfsd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\wasfsd

    RegDeleteKey HKUS\Software\DriveCleaner 2006 Free

    # 4 - ActiveX

    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{205FF73B-CA67-11D5-99DD-444553540006}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{F919FBD3-A96B-4679-AF26-F551439BB5FD}|Compatibility Flags|1024

    # 5 - Fichiers

    DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCPChk.dll|1
    DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCShell.dll|1
    DllUnregister C:\Program Files\ErrorSafe\df_fixer.dll|1
    DllUnregister C:\Program Files\ErrorSafe\df_proxy.dll|1
    DllUnregister C:\Program Files\ErrorSafe\ecc.dll|1
    DllUnregister C:\Program Files\ErrorSafe\esSPCheck.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FFWraper.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FixCore.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FiFxr5.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FTRec.dll|1
    DllUnregister C:\Program Files\ErrorSafe\MMFix.dll|1
    DllUnregister C:\Program Files\ErrorSafe\StrRes.dll|1
    DllUnregister C:\Program Files\SysProtect\compclr.dll|1
    DllUnregister C:\Program Files\SysProtect\df_fixer.dll|1
    DllUnregister C:\Program Files\SysProtect\df_proxy.dll|1
    DllUnregister C:\Program Files\SysProtect\FFWrapr.dll|1
    DllUnregister C:\Program Files\SysProtect\flfxr10.dll|1
    DllUnregister C:\Program Files\SysProtect\FTRec.dll|1
    DllUnregister C:\Program Files\SysProtect\FxCore.dll|1
    DllUnregister C:\Program Files\SysProtect\MMFx.dll|1
    DllUnregister C:\Program Files\SysProtect\StrRes.dll|1
    DllUnregister C:\Program Files\SystemDoctor 2006 Free\order.dll|1
    DllUnregister C:\Program Files\VirusGarde\Addons\popupg.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006\AsAgents.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006\shellext.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\AsAgents.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\shellext.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\uwas6chk.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\was6chk.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\avkernel.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\IEFWBHO.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\libfn.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\rpt.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\winpgi.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\compcln.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\df_fixer.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\df_proxy.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\ffCom.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FFWraper.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FileTypeRecognizer.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FixCore.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\MMFix.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\OEDrop.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\StrRes.dll|1
    DllUnregister C:\Program Files\Common Files\Companion Wizard\WapCHK.dll|1
    DllUnregister C:\Program Files\Common Files\WinAntiSpyware 2006\was6chk.dll|1
    DllUnregister C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll|1
    DllUnregister C:\Program Files\Common Files\WinSoftware\CrXML.dll|1
    DllUnregister C:\Program Files\Common Files\WinSoftware\PCheck.dll|1
    DllUnregister C:\Program Files\Fichiers communs\WinFixer 2005\uwappchk.dll|1
    DllUnregister C:\WINDOWS\system32\SpOrder.dll|1
    DllUnregister C:\WINDOWS\syst32.dll|1

    FileDelete C:\Documents and Settings\All Users\Bureau\WinAntiVirus*.lnk
    FileDelete C:\Documents and Settings\christelle\Application Data\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\christelle\Application Data\*errorsafe*.exe
    FileDelete C:\Documents and Settings\christelle\Application Data\*winantispyware*.exe
    FileDelete C:\Documents and Settings\christelle\Application Data\*winantivirus*.exe
    FileDelete C:\Documents and Settings\christelle\Application Data\install_fr*.exe
    FileDelete C:\Documents and Settings\christelle\Application Data\Microsoft\Internet Explorer\Quick Launch\SystemDoctor*.lnk
    FileDelete C:\Documents and Settings\christelle\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware*.lnk
    FileDelete C:\Documents and Settings\christelle\Application Data\setup_fr[1].exe
    FileDelete C:\Documents and Settings\christelle\Bureau\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\christelle\Bureau\DriveCleaner 2006 Free.lnk
    FileDelete C:\Documents and Settings\christelle\Bureau\ErrorGuard.lnk
    FileDelete C:\Documents and Settings\christelle\Bureau\ErrorSafe.lnk
    FileDelete C:\Documents and Settings\christelle\Bureau\ErrorSafe*.exe
    FileDelete C:\Documents and Settings\christelle\Bureau\SystemDoctor*.lnk
    FileDelete C:\Documents and Settings\christelle\Bureau\WinAntiSpyware*.lnk
    FileDelete C:\Documents and Settings\christelle\Bureau\WinFixer*.exe
    FileDelete C:\Documents and Settings\christelle\Bureau\WinFixer*.lnk
    FileDelete C:\Documents and Settings\christelle\Mes documents\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\christelle\Mes documents\*SystemDoctor*.exe
    FileDelete C:\Documents and Settings\christelle\Mes documents\*WinAntiVirusPro*.exe
    FileDelete C:\Program Files\*drivecleaner*.exe
    FileDelete C:\Program Files\*WinAntiVirusPro*.exe
    FileDelete C:\Program Files\Common Files\Companion Wizard\compwiz.exe
    FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
    FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK{*}.dll
    FileDelete C:\WINDOWS\46241234110.exe
    FileDelete C:\WINDOWS\service32.exe
    FileDelete C:\WINDOWS\syst32.dll
    FileDelete C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.1\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.2\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.3\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.4\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.5\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.6\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.7\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.8\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.9\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.10\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.11\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.12\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.13\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.14\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.15\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.16\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.17\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Prefetch\*winantispyware*.pf
    FileDelete C:\WINDOWS\system32\av.cpl
    FileDelete C:\WINDOWS\system32\df_kme.exe
    FileDelete C:\WINDOWS\system32\SpOrder.dll
    FileDelete C:\WINDOWS\system32\stera.exe
    FileDelete C:\WINDOWS\system32\stera.?o?
    FileDelete C:\WINDOWS\system32\drivers\ApiMon.sys
    FileDelete C:\WINDOWS\system32\drivers\df_kmd.sys
    FileDelete C:\WINDOWS\system32\drivers\ersd.sys
    FileDelete C:\WINDOWS\system32\drivers\erssdd.sys
    FileDelete C:\WINDOWS\system32\drivers\fopn.sys
    FileDelete C:\WINDOWS\system32\drivers\sscan.sys
    FileDelete C:\WINDOWS\system32\drivers\uwasfsd.sys
    FileDelete C:\WINDOWS\system32\drivers\vspf_hk5.sys
    FileDelete C:\WINDOWS\system32\drivers\vspf5.sys
    FileDelete C:\WINDOWS\system32\drivers\wasfsd.sys
    FileDelete C:\WINDOWS\system32\drivers\WFF.sys
    FileDelete C:\systemdoctor*.exe

    # 6 - Repertoires

    FolderDelete C:\Documents and Settings\christelle\Application Data\DriveCleaner Free
    FolderDelete C:\Documents and Settings\christelle\Application Data\systemdoctor 2006 free
    FolderDelete C:\Documents and Settings\christelle\Application Data\VirusGarde
    FolderDelete C:\Documents and Settings\christelle\Application Data\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\christelle\Application Data\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Corp
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DriveCleaner 2006 Free
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ErrorSafe
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\SystemDoctor 2006 Unregistered Version
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006 Scanner
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinFixer 2005
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\SysProtect
    FolderDelete C:\Program Files\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\erroguard
    FolderDelete C:\Program Files\Error Safe
    FolderDelete C:\Program Files\Error Safe Free
    FolderDelete C:\Program Files\ErrorSafe
    FolderDelete C:\Program Files\errorsafe free
    FolderDelete C:\Program Files\SysProtect Free
    FolderDelete C:\Program Files\SystemDoctor 2006
    FolderDelete C:\Program Files\SystemDoctor 2006 Free
    FolderDelete C:\Program Files\VirusGarde
    FolderDelete C:\Program Files\WinAntiSpyware 2006
    FolderDelete C:\Program Files\WinAntiSpyware 2006 Free
    FolderDelete C:\Program Files\WinAntiSpyware 2006 Scanner
    FolderDelete C:\Program Files\WinAntiVirus 2005
    FolderDelete C:\Program Files\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\WinAntiVirus Pro 2007
    FolderDelete C:\Program Files\WinFixer 2005
    FolderDelete C:\Program Files\WinPopupGuard 2005
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner Free
    FolderDelete C:\Program Files\Archivos comunes\Error Safe
    FolderDelete C:\Program Files\Archivos comunes\erroguard
    FolderDelete C:\Program Files\Archivos comunes\errorguard
    FolderDelete C:\Program Files\Archivos comunes\ErrorSafe
    FolderDelete C:\Program Files\Archivos comunes\SystemDoctor
    FolderDelete C:\Program Files\Archivos comunes\SystemDoctor 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2007
    FolderDelete C:\Program Files\Archivos comunes\WinFixer 2005
    FolderDelete C:\Program Files\Archivos comunes\WinSoftware
    FolderDelete C:\Program Files\Common Files\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Common Files\erroguard
    FolderDelete C:\Program Files\Common Files\errorguard
    FolderDelete C:\Program Files\Common Files\ErrorSafe
    FolderDelete C:\Program Files\Common Files\SysProtect
    FolderDelete C:\Program Files\Common Files\SystemDoctor 2006
    FolderDelete C:\Program Files\Common Files\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Common Files\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Common Files\WinFixer 2005
    FolderDelete C:\Program Files\Common Files\WinSoftware
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner Free
    FolderDelete C:\Program Files\Fichiers communs\Error Safe
    FolderDelete C:\Program Files\Fichiers communs\erroguard
    FolderDelete C:\Program Files\Fichiers communs\errorguard
    FolderDelete C:\Program Files\Fichiers communs\ErrorSafe
    FolderDelete C:\Program Files\Fichiers communs\ProtectionAssuree
    FolderDelete C:\Program Files\Fichiers communs\SystemDoctor
    FolderDelete C:\Program Files\Fichiers communs\SystemDoctor 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntivirus Pro 2007
    FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
    FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
    FolderDelete C:\Program Files\Fichiers communs\WinSoftware
    FolderDelete C:\UWA7PV
    FolderDelete C:\WinAntiVirus Pro 2006

    # 7 - Nettoyage

    Filedelete %USERPROFILE%\Cookies\*@*drivecleaner*.txt
    Filedelete %USERPROFILE%\Cookies\*@*errorsafe*.txt
    Filedelete %USERPROFILE%\Cookies\*@*systemdoctor*.txt
    Filedelete %USERPROFILE%\Cookies\*@*WinAntiSpyware*.txt
    Filedelete %USERPROFILE%\Cookies\*@*winantivirus*.txt
    Filedelete %USERPROFILE%\Cookies\*@*winfixer*.txt
    Filedelete %USERPROFILE%\Cookies\*@*yieldmanager*.txt

    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\systemdoctor.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\win-anti-virus-pro.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispy.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantiviruspro.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfirewall.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zone
    0
  9. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok refais hijack
    0
  10. chrisetsylvain Messages postés 112 Statut Membre
     
    voilà :

    Logfile of HijackThis v1.99.1
    Scan saved at 10:17, on 2008-03-29
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\a-squared free\a2service.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: cbxwttq - C:\WINDOWS\
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
    O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
    O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    tu n'as pas la bonne version

    refais un hijack avec cette version

    Télécharge sur le bureau

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    = Double-clic dessus pour l'installer
    = Clic Do a system scan and save the log
    =coller le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    @+
    0
  12. chrisetsylvain Messages postés 112 Statut Membre
     
    voilà c'est fait :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:23, on 2008-03-29
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\a-squared free\a2service.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - Winlogon Notify: cbxwttq - C:\WINDOWS\
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
    O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
    O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    0
  13. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    relance hijack et coche ceci

    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
    ensuite clique sur fix checked

    ensuite

    Télécharge:
    http://www.commentcamarche.net/telecharger/telecharger 218 avg anti spyware
    = Installer
    = Le lancer
    = Clic : Mise à jour
    ------
    = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel
    -------
    = Dans ANALYSE ( en forme de loupe )
    ==> Paramètres ==> sous COMMENT REAGIR==>clic sur Actions recommandées ==>Quarantaine
    ==> Clic : Analyse complète du système
    En fin de scan ( qui est assez long)
    ==> Clic Appliquer toutes les actions <== ceci Très important
    ==> Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau
    -------
    En mode normal
    colle le rapport

    ensuite fait un scan en ligne

    avec bitdefender et colle le rapport

    https://www.bitdefender.com/toolbox/

    un tuto
    http://pageperso.aol.fr/rginformatique/mapage/defender.htm
    @+
    0
    1. chrisetsylvain Messages postés 112 Statut Membre
       
      ---------------------------------------------------------
      AVG Anti-Spyware - Rapport d'analyse
      ---------------------------------------------------------

      + Créé à: 12:42 2008-03-29

      + Résultat de l'analyse:



      :mozilla.10:C:\Documents and Settings\christelle\Application Data\Mozilla\Firefox\Profiles\ggb5199y.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
      :mozilla.11:C:\Documents and Settings\christelle\Application Data\Mozilla\Firefox\Profiles\ggb5199y.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
      :mozilla.12:C:\Documents and Settings\christelle\Application Data\Mozilla\Firefox\Profiles\ggb5199y.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.


      Fin du rapport
      0
  14. chrisetsylvain Messages postés 112 Statut Membre
     
    BitDefender Online Scanner

    Rapport d'analyse généré à: Sat, Mar 29, 2008 - 13:49:57

    Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

    Statistiques

    Temps

    00:29:18

    Fichiers

    62556

    Directoires

    8401

    Secteurs de boot

    4

    Archives

    1035

    Paquets programmes

    8150

    Résultats

    Virus identifiés

    4

    Fichiers infectés

    9

    Fichiers suspects

    0

    Avertissements

    0

    Désinfectés

    0

    Fichiers effacés

    9

    Info sur les moteurs

    Définition virus

    1051843

    Version des moteurs

    AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

    Analyse des plugins

    15

    Archive des plugins

    33

    Unpack des plugins

    6

    E-mail plugins

    6

    Système plugins

    4

    Paramètres d'analyse

    Première action

    Désinfecté

    Seconde Action

    Supprimé

    Heuristique

    Oui

    Acceptez les avertissements

    Oui

    Extensions analysées

    exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

    Excludez les extensions

    Analyse d'emails

    Oui

    Analyse des Archives

    Oui

    Analyser paquets programmes

    Oui

    Analyse des fichiers

    Oui

    Analyse de boot

    Oui

    Fichier analysé

    Statut

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP276\A0048234.exe

    Détecté avec: Application.Generic.8516

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP276\A0048234.exe

    Echec de la désinfection

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP276\A0048234.exe

    Supprimé

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055370.dll

    Infecté par: Trojan.Vundo.DZZ

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055370.dll

    Echec de la désinfection

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055370.dll

    Supprimé

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055387.dll

    Infecté par: Trojan.Vundo.DZZ

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055387.dll

    Echec de la désinfection

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP327\A0055387.dll

    Supprimé

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP329\A0055600.dll

    Infecté par: Trojan.Vundo.EEH

    C:\System Volume Information\_restore{787DC6C3-51B9-452C-97E3-A31D31627396}\RP329\A0055600.dll

    Supprimé

    C:\WINDOWS\system32\awtsq.exe

    Infecté par: Trojan.Downloader.ConHook.AI

    C:\WINDOWS\system32\awtsq.exe

    Echec de la désinfection

    C:\WINDOWS\system32\awtsq.exe

    Supprimé

    C:\WINDOWS\system32\awvtt.exe

    Infecté par: Trojan.Downloader.ConHook.AI

    C:\WINDOWS\system32\awvtt.exe

    Echec de la désinfection

    C:\WINDOWS\system32\awvtt.exe

    Supprimé

    C:\WINDOWS\system32\pmnnm.exe

    Infecté par: Trojan.Downloader.ConHook.AI

    C:\WINDOWS\system32\pmnnm.exe

    Echec de la désinfection

    C:\WINDOWS\system32\pmnnm.exe

    Supprimé

    C:\WINDOWS\system32\ssqrs.exe

    Infecté par: Trojan.Downloader.ConHook.AI

    C:\WINDOWS\system32\ssqrs.exe

    Echec de la désinfection

    C:\WINDOWS\system32\ssqrs.exe

    Supprimé

    C:\WINDOWS\system32\vtstt.exe

    Infecté par: Trojan.Downloader.ConHook.AI

    C:\WINDOWS\system32\vtstt.exe

    Echec de la désinfection

    C:\WINDOWS\system32\vtstt.exe

    Supprimé
    0
  15. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    très bien as tu encore des soucis

    si non

    Tu peux supprimer tous les logiciels que nous avons utilisés
    va dans ajout/suppression de programes et dans programmes files
    pour vérifier

    ensuite fait ceci (IMPORTANT)

    =démarrer
    =panneau de configuration
    =système
    =onglet Restauration système
    =coche la case (Désactiver la restauration système)
    =redémarre l'ordinateur
    =réactive la ensuite
    @+
    0
    1. chrisetsylvain Messages postés 112 Statut Membre
       
      pour le moment tous va bien je fais ce que tu m'as dit et merci pour tout a+
      0
  16. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    parfait content pour toi
    marque ton sujet en résolu stp
    bye bye ;-)
    0