Envahie par des CID!!!

stella69200 Messages postés 16 Statut Membre -  
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité -
Bonjour,je suis envahie par des cid j'ai essayé la méthode avec lopxp mais rien n'y fait qui peut m'aider en me donnant la bonne solution?d'avance merci
Configuration: Windows XP
Internet Explorer 7.0

14 réponses

  1. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Salut,

    poste le ou les rapports lopxp
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Je te remerci je vais refaire un rapport et le poster donc dans le forum et qe va t'il se passer ensuite?
      0
  2. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    ensuite, tu feras ça :

    Clique sur ce lien
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
    pour télécharger le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJTInstall.exe pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la license en cliquant sur le bouton "I Accept"

    Ferme Hijackthis en cliquant sur la croix-rouge.

    Télécharge ce programme puis double clic dessus (ferme ton antivirus le temps du
    téléchargement s'il te détecte quoi que ce soit et réactive le après)
    http://www.suspectfile.com/systemscan/

    Clique sur Unselect all

    Coche uniquement ces cases :

    - Recent Files, 30 days

    - Registry run keys

    - Scheduled jobs

    - Services and drivers

    - Suspicious files

    - Include hijackthis log

    Puis clic sur scan now, sois patient.
    Une fois le scan terminé, un rapport va s'ouvrir, copie et colle son contenu ici et
    vérifie qu'il soit bien en entier, si besoin crée deux messages.

    Mais envoie déjà le rapport lop.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      J'ai envoyé le rapport il y a bientot une heure je vais maintenant faire ce que tu m'as indiqué A+
      0
  3. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    je ne sais pas ce que tu appelles "envoyer le rapport" mais tu peux constater qu'il n'est pas dans cette discussion.

    Copie le dans une réponse.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      # Rapport Lopxp fait le 08/04/2008 à 18:43:35
      # Exécuté dans : C:\Program Files\Lopxp
      # Version 3.06 - Maj du 05/02/2008

      Killing 'iexplore.exe'
      "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (3508)
      "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (3812)
      "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -Embedding (5216)


      ========== Listing des dossiers Application Data

      +- C:\Documents and Settings\Administrateur\Application Data

      2003-09-05 à 12:23:48 - Identities
      2003-09-05 à 12:23:48 - Microsoft
      2003-09-05 à 13:01:50 - Symantec

      +- C:\Documents and Settings\Administrateur\Local Settings\Application Data

      2003-09-05 à 12:23:48 - Microsoft

      +- C:\Documents and Settings\All Users\Application Data

      2008-02-07 à 10:49:19 - Adobe
      2005-04-27 à 11:34:28 - Autodesk
      2007-01-18 à 13:50:47 - BOONTY
      2006-02-23 à 21:50:18 - CanonBJ
      2006-12-10 à 09:27:02 - Exetender
      2006-09-05 à 15:04:06 - F-Secure
      2007-02-23 à 09:31:02 - Genimo
      2008-04-03 à 07:06:08 - Google
      2008-01-22 à 13:55:58 - HipSoft
      2006-12-03 à 09:57:49 - iWin
      2007-03-04 à 05:40:08 - JollyBear
      2008-03-17 à 05:20:03 - Kodak
      2006-10-31 à 09:31:05 - Macrovision
      2008-03-30 à 14:25:33 - Microsoft
      2008-03-13 à 09:41:26 - Microsoft Help
      2003-09-21 à 15:17:36 - MSN6
      2007-09-28 à 14:33:51 - MumboJumbo
      2007-11-28 à 17:40:24 - NeptunesAdve
      2005-11-08 à 15:05:27 - NFS Underground
      2007-04-12 à 14:37:11 - Oberongames
      2006-06-21 à 11:43:51 - PlayFirst
      2006-03-03 à 19:09:10 - QuickTime
      2007-04-30 à 08:53:25 - Runic
      2007-06-04 à 15:18:21 - Sandlot Games
      2003-09-05 à 12:57:01 - SBSI
      2006-08-09 à 06:29:47 - ScanSoft
      2008-01-13 à 09:59:52 - SecretsOfOlympus
      2007-08-13 à 15:41:45 - SpinTop Games
      2006-02-23 à 21:19:18 - SSScanAppDataDir
      2006-02-23 à 21:19:19 - SSScanWizard
      2005-02-23 à 20:30:32 - Symantec
      2007-06-15 à 15:00:15 - TEMP
      2007-04-02 à 14:39:37 - TERMINAL Studio
      2006-11-23 à 10:12:14 - Trymedia
      2003-09-28 à 10:09:42 - Ulead Systems
      2008-03-19 à 16:59:24 - Web Okay Five 01
      2006-06-23 à 20:00:02 - Windows Genuine Advantage
      2008-04-01 à 19:17:43 - WLInstaller
      2007-02-26 à 16:24:13 - Zylom

      +- C:\Documents and Settings\CHRYSTELLE\Application Data

      2007-01-31 à 11:34:10 - 7Wonders
      2008-01-21 à 18:45:26 - Adobe
      2007-02-22 à 09:08:08 - AdobeUM
      2007-01-31 à 11:15:31 - Angkor
      2006-07-23 à 14:34:34 - ArcSoft
      2006-05-02 à 11:49:33 - Beep
      2007-01-07 à 16:55:36 - Beep Industries
      2007-02-02 à 16:29:42 - Boomzap
      2008-01-16 à 20:18:21 - Canon
      2007-04-24 à 15:37:09 - DiVision Studios - Escaping Atlantis
      2006-02-19 à 16:24:10 - F-Secure
      2006-05-12 à 10:22:53 - funkitron
      2007-07-16 à 15:00:22 - Gaijin Ent
      2007-01-31 à 11:24:11 - Genimo
      2008-01-30 à 20:49:32 - Google
      2006-02-19 à 17:29:24 - Help
      2008-01-05 à 16:04:56 - Identities
      2007-06-22 à 08:41:24 - iWin
      2006-05-30 à 11:14:25 - Macromedia
      2007-09-04 à 15:01:33 - Magic Academy
      2006-04-30 à 20:43:48 - Magic Match
      2006-06-23 à 20:43:50 - Media Player Classic
      2007-01-28 à 17:24:04 - MessengerSkinner
      2008-04-02 à 02:32:13 - Microsoft
      2006-06-07 à 12:58:03 - MSN6
      2006-12-11 à 17:32:59 - PlayFirst
      2006-03-08 à 18:02:28 - Roxio
      2006-02-23 à 21:19:21 - ScanSoft
      2006-08-18 à 16:45:25 - Sonic
      2007-05-27 à 14:31:04 - Sun
      2003-09-05 à 13:01:50 - Symantec
      2005-07-06 à 19:00:32 - Template
      2006-04-28 à 19:58:26 - Ulead Systems
      2008-03-19 à 16:59:25 - user way surf
      2007-02-21 à 21:28:50 - vlc
      2006-06-21 à 15:55:28 - Wildfire
      2007-10-15 à 10:32:35 - Windows Desktop Search
      2008-01-05 à 16:04:55 - Zylom

      +- C:\Documents and Settings\CHRYSTELLE\Local Settings\Application Data

      2007-12-05 à 19:36:35 - Adobe
      2008-04-02 à 08:44:24 - ApplicationHistory
      2006-02-19 à 20:56:01 - Dell
      2008-01-17 à 20:35:09 - Google
      2006-02-19 à 17:29:24 - Help
      2006-02-18 à 20:17:28 - Identities
      2006-04-24 à 12:28:51 - IM
      2007-03-04 à 13:33:22 - JollyBear
      2008-04-02 à 02:52:24 - Microsoft
      2007-02-21 à 18:17:22 - Microsoft Help
      2007-10-15 à 11:06:12 - Windows Live Writer

      +- C:\Documents and Settings\FLORENT\Application Data

      2008-01-21 à 18:51:12 - Adobe
      2007-06-12 à 01:12:47 - AdobeUM
      2008-01-27 à 05:54:02 - ArcSoft
      2005-04-27 à 11:34:28 - Autodesk
      2007-04-01 à 06:07:37 - Babylon
      2008-03-25 à 21:24:28 - Canon
      2006-11-05 à 09:56:43 - Canvas Multi-Media
      2008-01-12 à 07:13:39 - dvdcss
      2006-05-13 à 14:40:28 - F-Secure
      2006-08-01 à 14:52:26 - Google
      2003-10-19 à 15:21:15 - Help
      2008-01-22 à 21:02:32 - Identities
      2003-09-28 à 09:27:28 - InterTrust
      2003-09-09 à 20:18:20 - InterVideo
      2006-12-03 à 09:57:49 - iWin
      2006-01-10 à 14:55:25 - Leadertech
      2006-11-27 à 15:53:47 - Macromedia
      2008-03-10 à 21:40:24 - Microsoft
      2007-04-03 à 05:02:31 - MSN6
      2004-06-04 à 15:37:21 - Orphée Développement
      2007-08-13 à 13:00:02 - PlayFirst
      2004-01-08 à 08:47:35 - Roxio
      2005-07-03 à 11:21:07 - RTE
      2006-08-09 à 06:29:47 - ScanSoft
      2006-08-25 à 07:58:01 - ShopperReports
      2006-08-19 à 05:24:37 - Sonic
      2007-06-13 à 05:14:26 - Sun
      2003-09-05 à 13:01:50 - Symantec
      2003-09-10 à 12:55:58 - Template
      2003-09-28 à 10:09:45 - Ulead Systems
      2008-03-19 à 16:59:26 - user way surf
      2007-06-02 à 06:36:23 - vlc
      2007-10-20 à 05:22:54 - Windows Desktop Search
      2007-12-16 à 05:36:10 - Windows Live Writer
      2005-11-06 à 07:35:23 - XnView
      2008-04-02 à 12:56:13 - ZapSpot
      2008-01-22 à 21:02:31 - Zylom

      +- C:\Documents and Settings\FLORENT\Local Settings\Application Data

      2008-01-28 à 21:13:52 - Adobe
      2008-04-07 à 21:09:35 - ApplicationHistory
      2005-04-27 à 11:34:28 - Autodesk
      2007-04-01 à 05:51:02 - Babylon
      2004-10-06 à 19:37:18 - BVRP Software
      2003-09-10 à 12:59:44 - Dell
      2006-07-31 à 07:19:13 - Google
      2003-10-26 à 10:28:30 - Help
      2003-09-17 à 19:26:04 - Identities
      2006-06-07 à 11:43:17 - IM
      2007-03-04 à 05:40:08 - JollyBear
      2008-03-30 à 14:32:10 - Microsoft
      2006-09-16 à 06:10:17 - Microsoft Help
      2007-01-07 à 06:04:41 - NFS Underground 2
      2007-02-04 à 16:27:16 - PCHealth
      2007-12-16 à 05:37:39 - Windows Live Writer

      +- C:\Documents and Settings\Invit‚\Application Data

      2003-09-05 à 12:23:48 - Identities
      2004-10-17 à 11:19:54 - InterVideo
      2005-02-06 à 07:01:42 - Microsoft
      2003-09-05 à 13:01:50 - Symantec
      2004-09-27 à 18:49:58 - Template

      +- C:\Documents and Settings\Invit‚\Local Settings\Application Data

      2005-01-10 à 20:29:15 - ApplicationHistory
      2003-09-05 à 12:23:48 - Microsoft

      +- C:\Documents and Settings\MARINA\Application Data

      2007-05-13 à 11:01:16 - Babylon
      2006-07-31 à 17:02:16 - F-Secure
      2006-07-31 à 17:01:56 - Google
      2004-10-04 à 16:31:52 - Help
      2003-09-05 à 12:23:48 - Identities
      2005-02-06 à 14:38:29 - InterVideo
      2006-07-31 à 17:02:18 - Microsoft
      2006-07-31 à 17:29:39 - ShopperReports
      2003-09-05 à 13:01:50 - Symantec

      +- C:\Documents and Settings\MARINA\Local Settings\Application Data

      2007-05-13 à 10:50:39 - ApplicationHistory
      2007-05-04 à 15:22:11 - Babylon
      2006-02-19 à 20:56:01 - Dell
      2006-07-31 à 17:01:56 - Google
      2004-10-04 à 16:31:52 - Help
      2007-03-04 à 08:41:00 - Microsoft

      +- C:\Documents and Settings\Propri‚taire\Local Settings\Application Data

      2006-09-19 à 07:08:05 - Microsoft

      ========== Listing du dossier Program Files

      +- C:\Program Files

      2003-11-12 à 12:32:28 - AbiSuite
      2007-11-16 à 17:25:02 - Absolutist_Games
      2006-11-26 à 08:11:35 - Acceleron
      2008-02-07 à 10:33:31 - Adobe
      2005-11-06 à 18:45:45 - AI-Software
      2005-04-27 à 11:37:37 - AnswerWorks 4.0
      2003-09-05 à 12:42:40 - Apoint
      2006-02-23 à 21:14:49 - ArcSoft
      2007-05-08 à 18:40:01 - Atari
      2008-03-28 à 18:31:33 - Auran
      2004-12-06 à 08:43:40 - AutoCAD 2005
      2005-04-27 à 11:52:57 - Autodesk
      2005-09-26 à 18:33:34 - Autodesk Architectural Desktop 2004
      2005-04-27 à 11:53:35 - Autodesk Architectural Desktop 2005
      2006-02-19 à 20:50:49 - BearPaw 2448CU Pro
      2006-02-23 à 21:45:14 - Canon
      2005-12-23 à 23:12:00 - Codemasters
      2006-07-28 à 12:15:38 - Common Files
      2003-09-05 à 12:24:06 - ComPlus Applications
      2004-08-30 à 17:50:03 - Cryo Interactive
      2007-03-24 à 12:52:17 - Dell
      2003-09-05 à 13:00:41 - Dell Computer
      2006-06-07 à 10:54:46 - DIFX
      2003-09-11 à 06:06:36 - directx
      2005-07-03 à 18:37:00 - Doom 3
      2006-08-25 à 15:12:16 - DXBall2
      2006-02-20 à 02:42:07 - e-Life Pal
      2006-07-28 à 12:22:43 - EA GAMES
      2005-10-16 à 15:49:30 - Eracha
      2007-06-25 à 14:55:08 - EZFace
      2008-04-01 à 19:21:53 - Fichiers communs
      2004-08-28 à 18:25:39 - Fox
      2006-02-19 à 21:03:27 - GameSpy Arcade
      2005-07-10 à 04:54:24 - Girosoft
      2008-02-02 à 21:02:43 - GOA
      2008-04-03 à 07:06:08 - Google
      2006-05-03 à 08:34:39 - HbTools_Icons
      2008-04-02 à 02:33:18 - InstallShield Installation Information
      2003-09-05 à 12:58:04 - Intel
      2008-02-14 à 20:06:57 - Internet Explorer
      2003-09-05 à 12:59:56 - InterVideo
      2003-09-05 à 13:00:58 - Jasc Software Inc
      2008-02-16 à 07:14:39 - Java
      2006-07-10 à 20:21:19 - Kit ADSL
      2006-05-08 à 17:39:57 - KraiSoft
      2008-04-08 à 16:43:42 - Lopxp
      2007-11-16 à 16:01:06 - Ludiclub
      2007-06-22 à 08:39:20 - Mes Jeux Téléchargés
      2006-02-20 à 10:57:49 - Messenger
      2006-11-02 à 17:22:33 - Micro Application
      2005-09-20 à 12:26:58 - Microids
      2003-09-05 à 12:24:12 - microsoft frontpage
      2005-09-26 à 18:39:08 - Microsoft Games
      2008-03-10 à 15:04:13 - Microsoft Office
      2007-10-15 à 09:40:15 - Microsoft SQL Server Compact Edition
      2008-03-10 à 15:01:44 - Microsoft Visual Studio
      2008-03-10 à 15:13:27 - Microsoft Works
      2008-03-10 à 14:44:47 - Microsoft.NET
      2006-01-09 à 21:11:34 - Mindscape
      2008-04-02 à 02:32:09 - Mio Technology
      2003-09-05 à 12:59:31 - Modem Helper
      2006-03-06 à 10:08:19 - Movie Maker
      2007-03-24 à 13:03:55 - MSECache
      2003-09-05 à 12:23:58 - MSN
      2006-06-23 à 09:06:03 - MSN Games
      2003-09-05 à 12:24:02 - MSN Gaming Zone
      2006-10-15 à 07:24:41 - MSXML 4.0
      2007-02-12 à 19:19:04 - MultiVoc
      2006-02-20 à 00:51:04 - NetMeeting
      2006-01-10 à 14:52:00 - NovaLogic
      2003-09-05 à 13:03:21 - Nullsoft
      2006-05-31 à 20:46:23 - Oberon Media
      2007-06-13 à 05:26:25 - Outlook Express
      2006-09-05 à 15:03:26 - Pack Securite
      2008-04-07 à 21:07:25 - Packard Bell Data Secure
      2006-12-19 à 06:17:42 - Player Metaboli
      2005-02-23 à 20:43:16 - Playtonium Jigsaw Enchanted Forest
      2003-10-16 à 19:58:39 - Pyro Studios
      2006-12-19 à 06:40:11 - Quadra
      2006-03-03 à 19:09:08 - QuickTime
      2003-09-05 à 13:03:05 - Real
      2006-11-02 à 19:35:29 - Realore
      2004-11-12 à 20:45:58 - ReflexiveArcade
      2003-09-05 à 13:03:38 - Roxio
      2007-10-29 à 10:47:19 - Samsung
      2006-02-23 à 21:18:31 - ScanSoft
      2005-11-03 à 17:41:19 - Sega
      2003-09-05 à 12:24:06 - Services en ligne
      2003-10-14 à 06:49:13 - Sierra OnLine
      2006-02-20 à 02:38:04 - SolidWorks
      2004-05-24 à 18:49:57 - TryMedia
      2006-04-12 à 19:25:55 - Ubi Soft
      2003-09-28 à 09:39:09 - Ulead Systems
      2006-10-26 à 17:34:12 - Ultranium4
      2003-09-05 à 12:24:12 - Uninstall Information
      2006-02-18 à 18:56:08 - USB Driver-Express
      2008-03-19 à 16:59:24 - user way surf
      2004-05-24 à 18:48:45 - ValuSoft
      2007-02-21 à 18:39:21 - VideoLAN
      2003-09-05 à 13:03:22 - Viewpoint
      2006-05-18 à 19:56:27 - WildTangent
      2008-03-30 à 14:27:07 - Windows Defender
      2007-10-15 à 09:36:21 - Windows Desktop Search
      2008-04-01 à 21:56:27 - Windows Live
      2007-10-13 à 16:16:14 - Windows Live Safety Center
      2007-08-13 à 08:34:15 - Windows Media Connect 2
      2007-08-13 à 08:34:10 - Windows Media Player
      2006-02-20 à 00:50:52 - Windows NT
      2006-09-16 à 12:33:31 - WindowsUpdate
      2003-09-05 à 12:24:12 - XEROX
      2007-05-16 à 02:20:01 - XnView
      2008-03-28 à 18:20:24 - Zylom Games
      2003-10-16 à 10:51:14 - Échecs

      ========== Tâches planifiées

      B5C0D6AA91B7561E.job: c:\docume~1\chryst~1\applic~1\userwa~1\nurb idol dart.exe
      MP Scheduled Scan.job: C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges
      Rappel d'abonnement 1 auprès de l'ISP.job: C:\WINDOWS\System32\OOBE\OOBEBALN.EXE /sys /i /n:1
      Scheduled scanning task.job: C:\PROGRA~1\PACKSE~1\ANTI-V~1\fsav.exe /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\PACKSE~1\ANTI-V~1\report.txt

      ========== Clés registre

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Five 01 else bias"="C:\Documents and Settings\All Users\Application Data\Web Okay Five 01\Five heart.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Frag Start"="C:\DOCUME~1\FLORENT\APPLIC~1\USERWA~1\Delete Clock Less.exe"


      ========== Bloqueur popups Internet Explorer

      *.zylom.com
      *.zylomgames.com
      www.facile-voyage.com
      www.caloga.com

      ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

      C:\Documents and Settings\All Users\Application Data\Web Okay Five 01
      C:\Documents and Settings\CHRYSTELLE\Application Data\user way surf
      C:\Documents and Settings\FLORENT\Application Data\user way surf
      C:\Program Files\user way surf
      C:\WINDOWS\tasks\B5C0D6AA91B7561E.job

      +- Registre:

      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Five 01 else bias"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Frag Start"=-




      - Fin du rapport -
      0
  4. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    pour éradiquer lop, fais ceci :

    va dans : Démarrer > Exécuter

    puis fais un copier/coller de :

    "%programfiles%\Lopxp\Lopxp.bat" /Fixme <= Guillemets y compris

    puis valide,

    Au menu, choisis l'option 1.

    Réponds oui si on te demande de confirmer la suppression d'un fichier, d'un dossier ou d'une clé.

    Poste le rapport stp
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Mon pc me dit qu'il ne trouve pas ce lien....
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    quel lien ?

    Clique sur démarrer puis sur exécuter

    puis fais un copier/coller de :

    "%programfiles%\Lopxp\Lopxp.bat" /Fixme

    (n'oublie pas les guillemets)

    puis valide,

    Au menu, choisis l'option 1.

    Réponds oui si on te demande de confirmer la suppression d'un fichier, d'un dossier ou d'une clé.

    Poste le rapport stp

    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Voila le rapport On m'a demandé de supprimer des fichiers et j'ai accepter comme tu me l'as indiqué Désolée de t'ennuyé mais je suis pas douée avec l'informatique alors je prends du temps pour faire les choses Maintenent que j'ai fait cela que dois faire?Merci# Rapport Lopxp fait le 08/04/2008 à 20:27:29
      # Exécuté dans : C:\Program Files\Lopxp
      # Version 3.06 - Maj du 05/02/2008


      ========== FixLog ==========


      +- Fichiers temporaires :
      Nettoyage effectué.



      ========== Listing des dossiers Application Data

      +- C:\Documents and Settings\Administrateur\Application Data

      2003-09-05 à 12:23:48 - Identities
      2003-09-05 à 12:23:48 - Microsoft
      2003-09-05 à 13:01:50 - Symantec

      +- C:\Documents and Settings\Administrateur\Local Settings\Application Data

      2003-09-05 à 12:23:48 - Microsoft

      +- C:\Documents and Settings\All Users\Application Data

      2008-02-07 à 10:49:19 - Adobe
      2005-04-27 à 11:34:28 - Autodesk
      2007-01-18 à 13:50:47 - BOONTY
      2006-02-23 à 21:50:18 - CanonBJ
      2006-12-10 à 09:27:02 - Exetender
      2006-09-05 à 15:04:06 - F-Secure
      2007-02-23 à 09:31:02 - Genimo
      2008-04-03 à 07:06:08 - Google
      2008-01-22 à 13:55:58 - HipSoft
      2006-12-03 à 09:57:49 - iWin
      2007-03-04 à 05:40:08 - JollyBear
      2008-03-17 à 05:20:03 - Kodak
      2006-10-31 à 09:31:05 - Macrovision
      2008-03-30 à 14:25:33 - Microsoft
      2008-03-13 à 09:41:26 - Microsoft Help
      2003-09-21 à 15:17:36 - MSN6
      2007-09-28 à 14:33:51 - MumboJumbo
      2007-11-28 à 17:40:24 - NeptunesAdve
      2005-11-08 à 15:05:27 - NFS Underground
      2007-04-12 à 14:37:11 - Oberongames
      2006-06-21 à 11:43:51 - PlayFirst
      2006-03-03 à 19:09:10 - QuickTime
      2007-04-30 à 08:53:25 - Runic
      2007-06-04 à 15:18:21 - Sandlot Games
      2003-09-05 à 12:57:01 - SBSI
      2006-08-09 à 06:29:47 - ScanSoft
      2008-01-13 à 09:59:52 - SecretsOfOlympus
      2007-08-13 à 15:41:45 - SpinTop Games
      2006-02-23 à 21:19:18 - SSScanAppDataDir
      2006-02-23 à 21:19:19 - SSScanWizard
      2005-02-23 à 20:30:32 - Symantec
      2007-06-15 à 15:00:15 - TEMP
      2007-04-02 à 14:39:37 - TERMINAL Studio
      2006-11-23 à 10:12:14 - Trymedia
      2003-09-28 à 10:09:42 - Ulead Systems
      2008-03-19 à 16:59:24 - Web Okay Five 01
      2006-06-23 à 20:00:02 - Windows Genuine Advantage
      2008-04-01 à 19:17:43 - WLInstaller
      2007-02-26 à 16:24:13 - Zylom

      +- C:\Documents and Settings\CHRYSTELLE\Application Data

      2007-01-31 à 11:34:10 - 7Wonders
      2008-01-21 à 18:45:26 - Adobe
      2007-02-22 à 09:08:08 - AdobeUM
      2007-01-31 à 11:15:31 - Angkor
      2006-07-23 à 14:34:34 - ArcSoft
      2006-05-02 à 11:49:33 - Beep
      2007-01-07 à 16:55:36 - Beep Industries
      2007-02-02 à 16:29:42 - Boomzap
      2008-01-16 à 20:18:21 - Canon
      2007-04-24 à 15:37:09 - DiVision Studios - Escaping Atlantis
      2006-02-19 à 16:24:10 - F-Secure
      2006-05-12 à 10:22:53 - funkitron
      2007-07-16 à 15:00:22 - Gaijin Ent
      2007-01-31 à 11:24:11 - Genimo
      2008-01-30 à 20:49:32 - Google
      2006-02-19 à 17:29:24 - Help
      2008-01-05 à 16:04:56 - Identities
      2007-06-22 à 08:41:24 - iWin
      2006-05-30 à 11:14:25 - Macromedia
      2007-09-04 à 15:01:33 - Magic Academy
      2006-04-30 à 20:43:48 - Magic Match
      2006-06-23 à 20:43:50 - Media Player Classic
      2007-01-28 à 17:24:04 - MessengerSkinner
      2008-04-02 à 02:32:13 - Microsoft
      2006-06-07 à 12:58:03 - MSN6
      2006-12-11 à 17:32:59 - PlayFirst
      2006-03-08 à 18:02:28 - Roxio
      2006-02-23 à 21:19:21 - ScanSoft
      2006-08-18 à 16:45:25 - Sonic
      2007-05-27 à 14:31:04 - Sun
      2003-09-05 à 13:01:50 - Symantec
      2005-07-06 à 19:00:32 - Template
      2006-04-28 à 19:58:26 - Ulead Systems
      2008-03-19 à 16:59:25 - user way surf
      2007-02-21 à 21:28:50 - vlc
      2006-06-21 à 15:55:28 - Wildfire
      2007-10-15 à 10:32:35 - Windows Desktop Search
      2008-01-05 à 16:04:55 - Zylom

      +- C:\Documents and Settings\CHRYSTELLE\Local Settings\Application Data

      2007-12-05 à 19:36:35 - Adobe
      2008-04-02 à 08:44:24 - ApplicationHistory
      2006-02-19 à 20:56:01 - Dell
      2008-01-17 à 20:35:09 - Google
      2006-02-19 à 17:29:24 - Help
      2006-02-18 à 20:17:28 - Identities
      2006-04-24 à 12:28:51 - IM
      2007-03-04 à 13:33:22 - JollyBear
      2008-04-02 à 02:52:24 - Microsoft
      2007-02-21 à 18:17:22 - Microsoft Help
      2007-10-15 à 11:06:12 - Windows Live Writer

      +- C:\Documents and Settings\FLORENT\Application Data

      2008-01-21 à 18:51:12 - Adobe
      2007-06-12 à 01:12:47 - AdobeUM
      2008-01-27 à 05:54:02 - ArcSoft
      2005-04-27 à 11:34:28 - Autodesk
      2007-04-01 à 06:07:37 - Babylon
      2008-03-25 à 21:24:28 - Canon
      2006-11-05 à 09:56:43 - Canvas Multi-Media
      2008-01-12 à 07:13:39 - dvdcss
      2006-05-13 à 14:40:28 - F-Secure
      2006-08-01 à 14:52:26 - Google
      2003-10-19 à 15:21:15 - Help
      2008-01-22 à 21:02:32 - Identities
      2003-09-28 à 09:27:28 - InterTrust
      2003-09-09 à 20:18:20 - InterVideo
      2006-12-03 à 09:57:49 - iWin
      2006-01-10 à 14:55:25 - Leadertech
      2006-11-27 à 15:53:47 - Macromedia
      2008-03-10 à 21:40:24 - Microsoft
      2007-04-03 à 05:02:31 - MSN6
      2004-06-04 à 15:37:21 - Orphée Développement
      2007-08-13 à 13:00:02 - PlayFirst
      2004-01-08 à 08:47:35 - Roxio
      2005-07-03 à 11:21:07 - RTE
      2006-08-09 à 06:29:47 - ScanSoft
      2006-08-25 à 07:58:01 - ShopperReports
      2006-08-19 à 05:24:37 - Sonic
      2007-06-13 à 05:14:26 - Sun
      2003-09-05 à 13:01:50 - Symantec
      2003-09-10 à 12:55:58 - Template
      2003-09-28 à 10:09:45 - Ulead Systems
      2008-03-19 à 16:59:26 - user way surf
      2007-06-02 à 06:36:23 - vlc
      2007-10-20 à 05:22:54 - Windows Desktop Search
      2007-12-16 à 05:36:10 - Windows Live Writer
      2005-11-06 à 07:35:23 - XnView
      2008-04-02 à 12:56:13 - ZapSpot
      2008-01-22 à 21:02:31 - Zylom

      +- C:\Documents and Settings\FLORENT\Local Settings\Application Data

      2008-01-28 à 21:13:52 - Adobe
      2008-04-07 à 21:09:35 - ApplicationHistory
      2005-04-27 à 11:34:28 - Autodesk
      2007-04-01 à 05:51:02 - Babylon
      2004-10-06 à 19:37:18 - BVRP Software
      2003-09-10 à 12:59:44 - Dell
      2006-07-31 à 07:19:13 - Google
      2003-10-26 à 10:28:30 - Help
      2003-09-17 à 19:26:04 - Identities
      2006-06-07 à 11:43:17 - IM
      2007-03-04 à 05:40:08 - JollyBear
      2008-03-30 à 14:32:10 - Microsoft
      2006-09-16 à 06:10:17 - Microsoft Help
      2007-01-07 à 06:04:41 - NFS Underground 2
      2007-02-04 à 16:27:16 - PCHealth
      2007-12-16 à 05:37:39 - Windows Live Writer

      +- C:\Documents and Settings\Invit‚\Application Data

      2003-09-05 à 12:23:48 - Identities
      2004-10-17 à 11:19:54 - InterVideo
      2005-02-06 à 07:01:42 - Microsoft
      2003-09-05 à 13:01:50 - Symantec
      2004-09-27 à 18:49:58 - Template

      +- C:\Documents and Settings\Invit‚\Local Settings\Application Data

      2005-01-10 à 20:29:15 - ApplicationHistory
      2003-09-05 à 12:23:48 - Microsoft

      +- C:\Documents and Settings\MARINA\Application Data

      2007-05-13 à 11:01:16 - Babylon
      2006-07-31 à 17:02:16 - F-Secure
      2006-07-31 à 17:01:56 - Google
      2004-10-04 à 16:31:52 - Help
      2003-09-05 à 12:23:48 - Identities
      2005-02-06 à 14:38:29 - InterVideo
      2006-07-31 à 17:02:18 - Microsoft
      2006-07-31 à 17:29:39 - ShopperReports
      2003-09-05 à 13:01:50 - Symantec

      +- C:\Documents and Settings\MARINA\Local Settings\Application Data

      2007-05-13 à 10:50:39 - ApplicationHistory
      2007-05-04 à 15:22:11 - Babylon
      2006-02-19 à 20:56:01 - Dell
      2006-07-31 à 17:01:56 - Google
      2004-10-04 à 16:31:52 - Help
      2007-03-04 à 08:41:00 - Microsoft

      +- C:\Documents and Settings\Propri‚taire\Local Settings\Application Data

      2006-09-19 à 07:08:05 - Microsoft

      ========== Listing du dossier Program Files

      +- C:\Program Files

      2003-11-12 à 12:32:28 - AbiSuite
      2007-11-16 à 17:25:02 - Absolutist_Games
      2006-11-26 à 08:11:35 - Acceleron
      2008-02-07 à 10:33:31 - Adobe
      2005-11-06 à 18:45:45 - AI-Software
      2005-04-27 à 11:37:37 - AnswerWorks 4.0
      2003-09-05 à 12:42:40 - Apoint
      2006-02-23 à 21:14:49 - ArcSoft
      2007-05-08 à 18:40:01 - Atari
      2008-03-28 à 18:31:33 - Auran
      2004-12-06 à 08:43:40 - AutoCAD 2005
      2005-04-27 à 11:52:57 - Autodesk
      2005-09-26 à 18:33:34 - Autodesk Architectural Desktop 2004
      2005-04-27 à 11:53:35 - Autodesk Architectural Desktop 2005
      2006-02-19 à 20:50:49 - BearPaw 2448CU Pro
      2006-02-23 à 21:45:14 - Canon
      2005-12-23 à 23:12:00 - Codemasters
      2006-07-28 à 12:15:38 - Common Files
      2003-09-05 à 12:24:06 - ComPlus Applications
      2004-08-30 à 17:50:03 - Cryo Interactive
      2007-03-24 à 12:52:17 - Dell
      2003-09-05 à 13:00:41 - Dell Computer
      2006-06-07 à 10:54:46 - DIFX
      2003-09-11 à 06:06:36 - directx
      2005-07-03 à 18:37:00 - Doom 3
      2006-08-25 à 15:12:16 - DXBall2
      2006-02-20 à 02:42:07 - e-Life Pal
      2006-07-28 à 12:22:43 - EA GAMES
      2005-10-16 à 15:49:30 - Eracha
      2007-06-25 à 14:55:08 - EZFace
      2008-04-01 à 19:21:53 - Fichiers communs
      2004-08-28 à 18:25:39 - Fox
      2006-02-19 à 21:03:27 - GameSpy Arcade
      2005-07-10 à 04:54:24 - Girosoft
      2008-02-02 à 21:02:43 - GOA
      2008-04-03 à 07:06:08 - Google
      2006-05-03 à 08:34:39 - HbTools_Icons
      2008-04-02 à 02:33:18 - InstallShield Installation Information
      2003-09-05 à 12:58:04 - Intel
      2008-02-14 à 20:06:57 - Internet Explorer
      2003-09-05 à 12:59:56 - InterVideo
      2003-09-05 à 13:00:58 - Jasc Software Inc
      2008-02-16 à 07:14:39 - Java
      2006-07-10 à 20:21:19 - Kit ADSL
      2006-05-08 à 17:39:57 - KraiSoft
      2008-04-08 à 18:28:34 - Lopxp
      2007-11-16 à 16:01:06 - Ludiclub
      2007-06-22 à 08:39:20 - Mes Jeux Téléchargés
      2006-02-20 à 10:57:49 - Messenger
      2006-11-02 à 17:22:33 - Micro Application
      2005-09-20 à 12:26:58 - Microids
      2003-09-05 à 12:24:12 - microsoft frontpage
      2005-09-26 à 18:39:08 - Microsoft Games
      2008-03-10 à 15:04:13 - Microsoft Office
      2007-10-15 à 09:40:15 - Microsoft SQL Server Compact Edition
      2008-03-10 à 15:01:44 - Microsoft Visual Studio
      2008-03-10 à 15:13:27 - Microsoft Works
      2008-03-10 à 14:44:47 - Microsoft.NET
      2006-01-09 à 21:11:34 - Mindscape
      2008-04-02 à 02:32:09 - Mio Technology
      2003-09-05 à 12:59:31 - Modem Helper
      2006-03-06 à 10:08:19 - Movie Maker
      2007-03-24 à 13:03:55 - MSECache
      2003-09-05 à 12:23:58 - MSN
      2006-06-23 à 09:06:03 - MSN Games
      2003-09-05 à 12:24:02 - MSN Gaming Zone
      2006-10-15 à 07:24:41 - MSXML 4.0
      2007-02-12 à 19:19:04 - MultiVoc
      2006-02-20 à 00:51:04 - NetMeeting
      2006-01-10 à 14:52:00 - NovaLogic
      2003-09-05 à 13:03:21 - Nullsoft
      2006-05-31 à 20:46:23 - Oberon Media
      2007-06-13 à 05:26:25 - Outlook Express
      2006-09-05 à 15:03:26 - Pack Securite
      2008-04-08 à 16:42:45 - Packard Bell Data Secure
      2006-12-19 à 06:17:42 - Player Metaboli
      2005-02-23 à 20:43:16 - Playtonium Jigsaw Enchanted Forest
      2003-10-16 à 19:58:39 - Pyro Studios
      2006-12-19 à 06:40:11 - Quadra
      2006-03-03 à 19:09:08 - QuickTime
      2003-09-05 à 13:03:05 - Real
      2006-11-02 à 19:35:29 - Realore
      2004-11-12 à 20:45:58 - ReflexiveArcade
      2003-09-05 à 13:03:38 - Roxio
      2007-10-29 à 10:47:19 - Samsung
      2006-02-23 à 21:18:31 - ScanSoft
      2005-11-03 à 17:41:19 - Sega
      2003-09-05 à 12:24:06 - Services en ligne
      2003-10-14 à 06:49:13 - Sierra OnLine
      2006-02-20 à 02:38:04 - SolidWorks
      2008-04-08 à 18:00:08 - Trend Micro
      2004-05-24 à 18:49:57 - TryMedia
      2006-04-12 à 19:25:55 - Ubi Soft
      2003-09-28 à 09:39:09 - Ulead Systems
      2006-10-26 à 17:34:12 - Ultranium4
      2003-09-05 à 12:24:12 - Uninstall Information
      2006-02-18 à 18:56:08 - USB Driver-Express
      2008-03-19 à 16:59:24 - user way surf
      2004-05-24 à 18:48:45 - ValuSoft
      2007-02-21 à 18:39:21 - VideoLAN
      2003-09-05 à 13:03:22 - Viewpoint
      2006-05-18 à 19:56:27 - WildTangent
      2008-03-30 à 14:27:07 - Windows Defender
      2007-10-15 à 09:36:21 - Windows Desktop Search
      2008-04-01 à 21:56:27 - Windows Live
      2007-10-13 à 16:16:14 - Windows Live Safety Center
      2007-08-13 à 08:34:15 - Windows Media Connect 2
      2007-08-13 à 08:34:10 - Windows Media Player
      2006-02-20 à 00:50:52 - Windows NT
      2006-09-16 à 12:33:31 - WindowsUpdate
      2003-09-05 à 12:24:12 - XEROX
      2007-05-16 à 02:20:01 - XnView
      2008-03-28 à 18:20:24 - Zylom Games
      2003-10-16 à 10:51:14 - Échecs

      ========== Tâches planifiées

      B5C0D6AA91B7561E.job: c:\docume~1\chryst~1\applic~1\userwa~1\nurb idol dart.exe
      MP Scheduled Scan.job: C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges
      Rappel d'abonnement 1 auprès de l'ISP.job: C:\WINDOWS\System32\OOBE\OOBEBALN.EXE /sys /i /n:1
      Scheduled scanning task.job: C:\PROGRA~1\PACKSE~1\ANTI-V~1\fsav.exe /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\PACKSE~1\ANTI-V~1\report.txt

      ========== Clés registre

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Five 01 else bias"="C:\Documents and Settings\All Users\Application Data\Web Okay Five 01\Five heart.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Frag Start"="C:\DOCUME~1\FLORENT\APPLIC~1\USERWA~1\Delete Clock Less.exe"


      ========== Bloqueur popups Internet Explorer

      *.zylom.com
      *.zylomgames.com
      www.facile-voyage.com
      www.caloga.com

      ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

      C:\Documents and Settings\All Users\Application Data\Web Okay Five 01
      C:\Documents and Settings\CHRYSTELLE\Application Data\user way surf
      C:\Documents and Settings\FLORENT\Application Data\user way surf
      C:\Program Files\user way surf
      C:\WINDOWS\tasks\B5C0D6AA91B7561E.job

      +- Registre:

      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Five 01 else bias"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Frag Start"=-




      - Fin du rapport -
      0
  7. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonsoir,

    ça n'a pas fonctionné.

    On change d'outil;

    Télécharger OTMoveIt2 par OldTimer
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

    * Enregistrer ce fichier sur le Bureau.
    * Faire un double clic sur OTMoveIt2.exe pour lancer l'exécution de l'outil. (Note: Si vous utilisez Vista, faire un clic droit sur le fichier puis choisir Exécuter en tant qu'administrateur).
    * Copier les lignes en gras ci-dessous dans le Presse-papiers en les sélectionnant TOUTES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier):

    C:\Documents and Settings\All Users\Application Data\Web Okay Five 01
    C:\Documents and Settings\CHRYSTELLE\Application Data\user way surf
    C:\Documents and Settings\FLORENT\Application Data\user way surf
    C:\Program Files\user way surf
    C:\WINDOWS\tasks\B5C0D6AA91B7561E.job
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Five 01 else bias
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Frag Start


    * Cliquer sur le bouton rouge Moveit!.
    * Copier tout ce qui se trouve dans la zone Results (sous la barre verte) dans le Presse-papiers en sélectionnant TOUTES LES LIGNES puis en appuyant simultanément sur les touches CTRL et C (ou, après les avoir sélectionnées, en faisant un clic droit puis en choisissant Copier), et coller ces résulats en réponse sur le forum.
    * Fermer OTMoveIt2

    Note: Si un fichier ou un dossier ne peut pas être déplacé immédiatement, un redémarrage sera peut-être nécessaire afin de terminer le processus de déplacement. Si le redémarrage de la machine vous est demandé, choisir Oui/Yes. Dans ce cas, après le redémarrage, ouvrir le Bloc-notes (Démarrer->Tous les programmes->Accessoires->Bloc-notes), cliquer sur Fichier->Ouvrir, dans la zone "Nom du fichier" taper *.log et appuyer sur la touche Entrée, naviguer jusqu'au dossier C:\_OTMoveIt\MovedFiles, puis ouvrir le fichier .log le plus récent; ensuite faire un copier/coller du contenu de ce document en réponse sur le forum.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Bonsoir désolée pour le résultat de ce que tu m'as demandé de faire C:\Documents and Settings\All Users\Application Data\Web Okay Five 01
      C:\Documents and Settings\CHRYSTELLE\Application Data\user way surf
      C:\Documents and Settings\FLORENT\Application Data\user way surf
      C:\Program Files\user way surf
      C:\WINDOWS\tasks\B5C0D6AA91B7561E.job
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Five 01 else bias
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Frag Start


      OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04092008_003013 Je te laisse et on reparle de tout ca demain et encore merci
      0
  8. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    tu continues comme ça :

    tu redémarres l'ordi.

    Clique sur ce lien
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
    pour télécharger le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Double-clique sur HJTInstall.exe pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la license en cliquant sur le bouton "I Accept"

    Choisis l'option "Do a system scan and save a log file"

    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

    Colle le rapport que tu viens de copier sur ce forum

    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
    http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      J'ai fait ce que tu m'as dit mais es ce que je dois aller sur le lien tutoriaux? Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 01:12:19, on 09/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      C:\Program Files\Pack Securite\Anti-Virus\FSGK32.EXE
      C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      C:\Program Files\Pack Securite\Common\FSMA32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fssm32.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Pack Securite\Common\FSMB32.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Pack Securite\Common\FCH32.EXE
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Pack Securite\Common\FAMEH32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fsrw.exe
      C:\Program Files\Pack Securite\FSPC\fspc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsav32.exe
      C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\pctspk.exe
      C:\Program Files\Apoint\Apoint.exe
      C:\WINDOWS\System32\DSentry.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Pack Securite\Common\FSM32.EXE
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Apoint\Apntex.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\PROGRA~1\PACKSE~1\ANTI-S~1\fsaw.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
      C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
      O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Pack Securite\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [NI.UWAS6V_0001_N91M2208] "c:\documents and settings\chrystelle\application data\winantispyware2006freeinstall_fr[1].exe" -nag
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [zvrxoq] c:\windows\system32\zvrxoq.exe zvrxoq
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RTEGPRS] "C:\Program Files\Fichiers communs\RTE\RTEGPRS.exe" tray
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\prosvsys.exe /res
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      O4 - Global Startup: Pack Securite.lnk = C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Pack Securite\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://m6video.m6.fr/1click/install/files/installer2.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
      O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/uploader/ImageUploader3.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/net/Import/ImageUploader3.cab
      O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab
      O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Pack Securite (BackWeb Plug-in - 361343) - BackWeb Technologies Inc. - C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Pack Securite\FSPC\fshttps\fshttps.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
  9. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re

    exit CID. Il faut traiter Navipromo.

    Clique sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    pour télécharger navilog1.exe.

    Choisis Enregistrer

    et enregistre-le sur ton bureau.

    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    La suite au jour.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Bonjour voila le rapport et encore merci pour ton aide Search Navipromo version 3.5.2 commencé le 09/04/2008 à 9:36:00,42

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "FLORENT"

      Mise à jour le 29.03.2008 à 22h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***




      *** Recherche dossiers dans C:\WINDOWS ***

      C:\WINDOWS\msskinner trouvé !


      *** Recherche dossiers dans C:\Program Files ***



      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***




      *** Recherche dossiers dans "C:\Documents and Settings\FLORENT\applic~1" ***



      *** Recherche dossiers dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" ***



      *** Recherche dossiers dans "C:\Documents and Settings\FLORENT\menudm~1\progra~1" ***


      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 ***


      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé



      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\CHRYST~1\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\MARINA\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\PROPRI~1\locals~1\applic~1" *



      *** Recherche fichiers ***


      C:\WINDOWS\pack.epk trouvé !


      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      zvrxoq.dat trouvé !
      zvrxoq_nav.dat trouvé !
      zvrxoq_navps.dat trouvé !

      * Dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" :


      * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


      * Dans "C:\DOCUME~1\CHRYST~1\locals~1\applic~1" :


      * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :


      * Dans "C:\DOCUME~1\MARINA\locals~1\applic~1" :


      * Dans "C:\DOCUME~1\PROPRI~1\locals~1\applic~1" :


      3)Recherche Certificats :

      Certificat Egroup trouvé !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :



      *** Analyse terminée le 09/04/2008 à 12:17:35,29 ***
      0
  10. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonjour,

    Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
    Au menu principal, choisis 2 et valide.

    Le fix va t'informer qu'il va alors redémarrer ton PC
    Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
    Appuie sur une touche comme demandé.
    (si ton Pc ne redémarre pas automatiquement, fais le toi même)
    Au redémarrage de ton PC, choisis ta session habituelle.

    Patiente jusqu'au message :
    *** Nettoyage Termine le ..... ***
    Le blocnote va s'ouvrir.
    Sauvegarde le rapport de manière à le retrouver
    Referme le blocnote. Ton bureau va réapparaitre

    PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
    Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
    Tape explorer et valide. Celà te fera apparaitre ton bureau.

    Poste le rapport dans ta réponse avec un nouveau rapport Hijackthis.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Re voici les deux rapports en esperant que je te donne pas trop du fil a tordre LOL Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:09:25, on 09/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: NormalClean Navipromo version 3.5.2 commencé le 09/04/2008 à 14:46:14,96

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "FLORENT"

      Mise à jour le 29.03.2008 à 22h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS



      *** fsbl1.txt non trouvé ***
      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans C:\WINDOWS\System32 *


      * Suppression dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" *


      * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


      * Suppression dans "C:\DOCUME~1\CHRYST~1\locals~1\applic~1" *


      * Suppression dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *


      * Suppression dans "C:\DOCUME~1\MARINA\locals~1\applic~1" *


      * Suppression dans "C:\DOCUME~1\PROPRI~1\locals~1\applic~1" *



      *** Suppression dossiers dans C:\WINDOWS ***

      C:\WINDOWS\msskinner ...suppression...
      C:\WINDOWS\msskinner supprimé !


      *** Suppression dossiers dans C:\Program Files ***


      *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***


      *** Suppression dossiers dans "C:\Documents and Settings\FLORENT\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\FLORENT\menudm~1\progra~1" ***


      *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 ***



      *** Suppression fichiers ***

      C:\WINDOWS\pack.epk supprimé !

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu C:\Documents and Settings\FLORENT\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :


      * Dans C:\WINDOWS\system32 *

      zvrxoq.dat trouvé !
      Copie zvrxoq.dat réalisée avec succès !
      zvrxoq.dat supprimé !

      zvrxoq_nav.dat trouvé !
      Copie zvrxoq_nav.dat réalisée avec succès !
      zvrxoq_nav.dat supprimé !

      zvrxoq_navps.dat trouvé !
      Copie zvrxoq_navps.dat réalisée avec succès !
      zvrxoq_navps.dat supprimé !


      * Dans "C:\Documents and Settings\FLORENT\locals~1\applic~1" *


      * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


      * Dans "C:\DOCUME~1\CHRYST~1\locals~1\applic~1" *


      * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *


      * Dans "C:\DOCUME~1\MARINA\locals~1\applic~1" *


      * Dans "C:\DOCUME~1\PROPRI~1\locals~1\applic~1" *


      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok


      *** Certificats ***

      Certificat Egroup supprimé !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Nettoyage terminé le 09/04/2008 à 15:01:55,17 ***


      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      C:\Program Files\Pack Securite\Anti-Virus\FSGK32.EXE
      C:\Program Files\Pack Securite\Common\FSMA32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fssm32.exe
      C:\Program Files\Pack Securite\Common\FSMB32.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Pack Securite\Common\FCH32.EXE
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Pack Securite\Common\FAMEH32.EXE
      C:\Program Files\Pack Securite\FSPC\fspc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsrw.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fsav32.exe
      C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\WINDOWS\system32\pctspk.exe
      C:\Program Files\Apoint\Apoint.exe
      C:\WINDOWS\System32\DSentry.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Pack Securite\Common\FSM32.EXE
      C:\Program Files\Apoint\Apntex.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\PROGRA~1\PACKSE~1\ANTI-S~1\fsaw.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
      C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
      O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Pack Securite\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [NI.UWAS6V_0001_N91M2208] "c:\documents and settings\chrystelle\application data\winantispyware2006freeinstall_fr[1].exe" -nag
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RTEGPRS] "C:\Program Files\Fichiers communs\RTE\RTEGPRS.exe" tray
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      O4 - Global Startup: Pack Securite.lnk = C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Pack Securite\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://m6video.m6.fr/1click/install/files/installer2.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
      O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/uploader/ImageUploader3.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/net/Import/ImageUploader3.cab
      O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab
      O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Pack Securite (BackWeb Plug-in - 361343) - BackWeb Technologies Inc. - C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Pack Securite\FSPC\fshttps\fshttps.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
  11. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonjour,

    pas de soucis, j'ai connu pire et ça s'améliore.

    Relance HijackThis.

    Choisis Do a scan only

    Coche la case devant les lignes suivantes

    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [NI.UWAS6V_0001_N91M2208] "c:\documents and settings\chrystelle\application data\winantispyware2006freeinstall_fr[1].exe" -nag
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/

    Ferme toutes les fenêtres (hormis HijackThis), y compris ton navigateur.

    Clique sur fix checked.

    Ferme Hijackthis.

    Télécharge Brute Force Uninstaller (de Merijn) ici: http://www.merijn.org/files/bfu.zip
    Créé un nouveau dossier directement à la racine de ton disque dur ou l'endroit qui te convient, nomme ce dossier BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (par exemple C:\BFU)
    Ensuite, télécharge Winsoftware.bfu (de lazzzy) :
    Fais un clik droit ici : : http://www.alt-shift-return.org/Info/Fichiers/Winsoftware.bfu
    et choisis "Enregistrer la cible sous..." afin de télécharger Winsoftware.bfu (delazzzy).
    Sauvegarde dans le dossier créé (C:\BFU).
    **Note : si tu utilises Internet Explorer ; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers".

    Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : Winsoftware.bfu et BFU.exe (très important).

    -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-

    Tu as une démo animée ici (merci balltrap34):
    http://perso.orange.fr/rginformatique/section%20virus/bfu%20demo.htm
    _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
    Lance "Brute Force Uninstaller" en double-cliquant BFU.exe (Dans le dossier C:\BFU)
    - Clique sur le petit dossier jaune, et clique sur : Winsoftware.bfu
    - Coches la case Show log after scrïpt ends
    - Clique sur Execute pour que le fix fasse son boulot :-) Attends que le message Complete scrïpt execution apparaîsse et clique sur OK.
    Un rapport va s'afficher dans la fenetre du programme, copie et colle dans le bloc-notes, puis sauvegardes le, tu le posteras plus tard sur le forum.
    Clique Exit pour fermer le programme BFU.

    Avec l'explorateur Windows, cherche :

    c:\documents and settings\chrystelle\application data\winantispyware2006freeinstall_fr[1].exe

    fais un clic droit dessus et supprimer.

    poste le rapport de BFU avec un nouveau rapport Hijackthis.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Re... voici à nouveau mes rapports par contre mon pc n'a pas trouvé c:\documents and settings\chrystelle\application data\winantispyware2006freeinstall_fr[1].exe
      Logfile of Trend Micro HijackThis v2.0.2BFU v1.11.0
      Windows XP SP2 (WinNT 5.01.2600 SP2)
      Script started at 19:16:09, on 09/04/2008

      Option Unload Explorer: Yes
      Success: ProcessKillByPID 2552
      Success: ProcessKill C:\WINDOWS\explorer.exe|1
      Warning: The following line has unexpanded aliases and will be skipped: # Winsoftware.bfu
      # lazzzy 20/09/2006
      # Ce script cible ErrorSafe / Winfixer / ErrorGuard / DriveCleaner / SystemDoctor / WinAntiVirusPro / WinAntiSpyware / SysProtect

      OptionUnloadShell

      # 1 - Processus

      ProcessKill \AdwareProtector.exe|1
      ProcessKill \ErrorGuard.exe|1
      ProcessKill \ERScw.exe|1
      ProcessKill C:\Program Files\WinAntiVirus Pro 2006\fat.exe|1
      ProcessKill \sd2006.exe|1
      ProcessKill \SDR6cw.exe|1
      ProcessKill \SDRmon.exe|1
      ProcessKill C:\Program Files\SystemDoctor 2006 Free\startmon.exe|1
      ProcessKill C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe|1
      ProcessKill C:\Program Files\systemdoctor 2006 free\updater.exe|1
      ProcessKill C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe|1
      ProcessKill C:\Program Files\DriveCleaner 2006 Free\udc6cw.exe|1
      ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe|1
      ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe|1
      ProcessKill C:\Program Files\WinAntiSpyware 2006 Scanner\updater.exe|1
      ProcessKill C:\Program Files\SystemDoctor 2006 Free\usdr6cw.exe|1
      ProcessKill C:\Program Files\SysProtect Free\USYP.exe|1
      ProcessKill C:\Program Files\WinAntiVirus Pro 2006\uwa6pcw.exe|1
      ProcessKill uwasffNT.exe|1
      ProcessKill \was6.exe|1
      ProcessKill \WinAV.exe|1
      ProcessKill \WinPG2005.exe|1

      # 2 - Services

      ServiceStop FWSvc
      ServiceDisable FWSvc
      ServiceDelete FWSvc

      # 3 - Registre

      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|AdwareProtector
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe Free
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafeFree
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1212
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect Free
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005
      RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinPopupGuard 2005

      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cmonitor
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|CompanionWizard
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6_check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6cw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6v_check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6Y_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DriveCleaner 2006 Free
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorGuard
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafe
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERS_check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERScw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fat.exe
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Firewall
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRV_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRY_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MNI.UWFX5LP_0001_0614
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UAVIFR_0001_N105M2404
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERS_0001_NI57M1124
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N57M0112
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N68M1602
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_LP
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N68M0602
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91M2107
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91S2108
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_9999_N91S1912
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSY_0001_N68M0602
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6PV_0001_N108M0207
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6P_5555_N122M0312
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6PV_0001_N122M1202
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGESV_0001_N122M0303
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ni.usyp
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0002_N91M1708
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0003_N91M0908
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PV_0001_N91M2107
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PY_0001_N73M0604
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N91M0510
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N96M0206
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N76M1904
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N91M2208
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6Y_0001_N91M2208
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_0802
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1412
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX6_0001_N68M2301
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|PAS_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|rtasks
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Salestart
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6cw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6V_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6Y_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006 Free
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|udc6cw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|UERScw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uga6pcw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|usdr6cw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwa6pcw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwas6cw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wa6pcw
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WA6PV_Check
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Free
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Scanner
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirusPro2006
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirus Pro 2007
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005

      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat.exe
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat_reinstall
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|WinAntiSpyware 2006 Scanner

      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\ErrorSafe\esPCheck.dll
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\common files\winantivirus pro 2006\wapchk.dll
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\WinAntiSpyware 2006 Scanner\uwasffNT.exe
      RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\WINDOWS\system32\drivers\uwasfsd.sys

      RegDeleteKey HKCR\antiviruscom.avofficeprotect
      RegDeleteKey HKCR\antiviruscom.avofficeprotect.1
      RegDeleteKey HKCR\avexplorer.shellextension
      RegDeleteKey HKCR\avexplorer.shellextension.2
      RegDeleteKey HKCR\avexplorer.shellextension\curver
      RegDeleteKey HKCR\checkprod.checkproduct
      RegDeleteKey HKCR\CheckProduct2.CheckProduct
      RegDeleteKey HKCR\CheckProduct2.CheckProduct.1
      RegDeleteKey HKCR\ComCleanCor.AppCleane
      RegDeleteKey HKCR\ComCleanCor.AppCleane.1
      RegDeleteKey HKCR\ComCleanCor.CQuickScan
      RegDeleteKey HKCR\ComCleanCor.CQuickScan.1
      RegDeleteKey HKCR\ComCleanCor.FileCleane
      RegDeleteKey HKCR\ComCleanCor.InetCleane
      RegDeleteKey HKCR\ComCleanCor.InetCleane.1
      RegDeleteKey HKCR\ComCleanCor.RegCleane
      RegDeleteKey HKCR\ComCleanCor.RegCleane.1
      RegDeleteKey HKCR\ComCleanCor.SystemCleane
      RegDeleteKey HKCR\ComCleanCor.SystemCleane.1
      RegDeleteKey HKCR\ComCleanCore.FileClean.1
      RegDeleteKey HKCR\CompCleanCore.AppCleaner
      RegDeleteKey HKCR\CompCleanCore.AppCleaner.1
      RegDeleteKey HKCR\CompCleanCore.CCQuickScan
      RegDeleteKey HKCR\CompCleanCore.CCQuickScan.1
      RegDeleteKey HKCR\CompCleanCore.FileCleaner
      RegDeleteKey HKCR\CompCleanCore.FileCleaner.1
      RegDeleteKey HKCR\CompCleanCore.InetCleaner
      RegDeleteKey HKCR\CompCleanCore.InetCleaner.1
      RegDeleteKey HKCR\CompCleanCore.RegCleaner
      RegDeleteKey HKCR\CompCleanCore.RegCleaner.1
      RegDeleteKey HKCR\CompCleanCore.SystemCleaner
      RegDeleteKey HKCR\CompCleanCore.SystemCleaner.1
      RegDeleteKey HKCR\df_fixer.Fixer
      RegDeleteKey HKCR\df_fixer.Fixer.1
      RegDeleteKey HKCR\df_proxy.DriverManipulate
      RegDeleteKey HKCR\df_proxy.DriverManipulate.1
      RegDeleteKey HKCR\df_fix.Fix
      RegDeleteKey HKCR\df_fix.Fix.1
      RegDeleteKey HKCR\df_prx.DriverManipulat
      RegDeleteKey HKCR\df_prx.DriverManipulat.1
      RegDeleteKey HKCR\escompcleancore.esappcleaner
      RegDeleteKey HKCR\escompcleancore.esappcleaner.1
      RegDeleteKey HKCR\escompcleancore.esccquickscan
      RegDeleteKey HKCR\escompcleancore.esccquickscan.1
      RegDeleteKey HKCR\escompcleancore.esfilecleaner
      RegDeleteKey HKCR\escompcleancore.esfilecleaner.1
      RegDeleteKey HKCR\escompcleancore.esinetcleaner
      RegDeleteKey HKCR\escompcleancore.esinetcleaner.1
      RegDeleteKey HKCR\escompcleancore.esregcleaner
      RegDeleteKey HKCR\escompcleancore.esregcleaner.1
      RegDeleteKey HKCR\escompcleancore.essystemcleaner
      RegDeleteKey HKCR\escompcleancore.essystemcleaner.1
      RegDeleteKey HKCR\esdf_fixer.esfixer
      RegDeleteKey HKCR\esdf_fixer.esfixer.1
      RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate
      RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate.1
      RegDeleteKey HKCR\esffwraper.esffenginwraper
      RegDeleteKey HKCR\esffwraper.esffenginwraper.1
      RegDeleteKey HKCR\esfixcore.esmmfixcore
      RegDeleteKey HKCR\esfixcore.esmmfixcore.1
      RegDeleteKey HKCR\esmmfixctrl.escofixengine
      RegDeleteKey HKCR\esmmfixctrl.escofixengine.1
      RegDeleteKey HKCR\esspchck.esspchck
      RegDeleteKey HKCR\esspchck.esspchck.1
      RegDeleteKey HKCR\esspcheck.esspcheck
      RegDeleteKey HKCR\esspcheck.esspcheck.1
      RegDeleteKey HKCR\FFCom.FlFixer
      RegDeleteKey HKCR\FFWraper.FFEnginWraper
      RegDeleteKey HKCR\FFWrap.FEnginWrape
      RegDeleteKey HKCR\FFWrap.FEnginWrape.1
      RegDeleteKey HKCR\FFWraper.FFEnginWraper.1
      RegDeleteKey HKCR\FFxr_21.FFixr21
      RegDeleteKey HKCR\FixCor.MMFxCor
      RegDeleteKey HKCR\FixCor.MMFxCor.1
      RegDeleteKey HKCR\FixCore.MMFixCore
      RegDeleteKey HKCR\FixCore.MMFixCore.1
      RegDeleteKey HKCR\FlFxr3.FlFixer3
      RegDeleteKey HKCR\flfxr5.flfixer5
      RegDeleteKey HKCR\FlFxr15.FlFixer15
      RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r
      RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r.1
      RegDeleteKey HKCR\FWraper.FFEnginWraper
      RegDeleteKey HKCR\FWraper.FFEnginWraper.1
      RegDeleteKey HKCR\FxCor_e.MMFixCor_e.1
      RegDeleteKey HKCR\FxCor_e.MMFixCor_e
      RegDeleteKey HKCR\FxCore.MMFixCore
      RegDeleteKey HKCR\FxCore.MMFixCore.1
      RegDeleteKey HKCR\iefwbho.iefw
      RegDeleteKey HKCR\iefwbho.iefw.2
      RegDeleteKey HKCR\Install.Install
      RegDeleteKey HKCR\Install.Install.1
      RegDeleteKey HKCR\MMFixCtrl.CoFixEngine
      RegDeleteKey HKCR\MMFixCtrl.CoFixEngine.1
      RegDeleteKey HKCR\MMFx.CoFxEngin
      RegDeleteKey HKCR\MMFx.CoFxEngin.1
      RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e
      RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e.1
      RegDeleteKey HKCR\systemdoctor.free
      RegDeleteKey HKCR\UWFX6PCheck.UWFX6PCheck.2
      RegDeleteKey HKCR\UWFXCheck.UWFXCheck
      RegDeleteKey HKCR\UWFXCheck.UWFXCheck.1
      RegDeleteKey HKCR\wap6.pcheck
      RegDeleteKey HKCR\wap6.pcheck.1
      RegDeleteKey HKCR\winpgintegrator.ieintegrator
      RegDeleteKey HKCR\winpgintegrator.ieintegrator.1

      RegDeleteKey HKCR\AppID\{25A3C995-10C8-474B-A167-99460AB4AB2B}
      RegDeleteKey HKCR\AppID\{287A2BAD-6590-4EFF-9BBC-494385664A73}
      RegDeleteKey HKCR\AppID\{290B5B73-4963-4BA1-9D2D-07CB566CB7FA}
      RegDeleteKey HKCR\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9}
      RegDeleteKey HKCR\AppID\{3C132D19-6103-4fc3-8326-34E13EE9E2C0}
      RegDeleteKey HKCR\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
      RegDeleteKey HKCR\AppID\{8C65AEF6-E413-4314-815B-82717A3F1603}
      RegDeleteKey HKCR\AppID\{AAB0BA34-6D48-425f-B4B4-98F158CB61F1}
      RegDeleteKey HKCR\AppID\{DED71DE6-0575-4556-8311-A506B116A1A9}
      RegDeleteKey HKCR\AppID\{E8928E69-C050-42A9-8884-94DE85E888A2}
      RegDeleteKey HKCR\AppID\{E11FF09D-39AF-4613-86AD-F3217E576571}
      RegDeleteKey HKCR\AppID\CheckProduct2.DLL
      RegDeleteKey HKCR\AppID\compcln.dll
      RegDeleteKey HKCR\AppID\compclr.dll
      RegDeleteKey HKCR\AppID\FFWrapr.DLL
      RegDeleteKey HKCR\AppID\FFWraper.DLL
      RegDeleteKey HKCR\AppID\FixCore.DLL
      RegDeleteKey HKCR\AppID\FxCr.DLL
      RegDeleteKey HKCR\AppID\MFix.DLL
      RegDeleteKey HKCR\AppID\MMFixCtrl.DLL
      RegDeleteKey HKCR\AppID\winpgi.dll appid

      RegDeleteKey HKCR\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
      RegDeleteKey HKCR\CLSID\{0ba379c6-0efd-4a28-932c-d20469052fd9}
      RegDeleteKey HKCR\CLSID\{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
      RegDeleteKey HKCR\CLSID\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
      RegDeleteKey HKCR\CLSID\{151a44b0-fc2d-4a02-bbbc-6b372f2f659c}
      RegDeleteKey HKCR\CLSID\{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
      RegDeleteKey HKCR\CLSID\{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
      RegDeleteKey HKCR\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
      RegDeleteKey HKCR\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
      RegDeleteKey HKCR\CLSID\{205FF73B-CA67-11D5-99DD-444553540006}
      RegDeleteKey HKCR\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
      RegDeleteKey HKCR\CLSID\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
      RegDeleteKey HKCR\CLSID\{356af2e9-8874-4c60-a3d8-0cb516c9e747}
      RegDeleteKey HKCR\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
      RegDeleteKey HKCR\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
      RegDeleteKey HKCR\CLSID\{5284ac2a-ef00-4750-9b82-b5b907d26536}
      RegDeleteKey HKCR\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
      RegDeleteKey HKCR\CLSID\{53ABACCB-434C-4756-A02B-8C2A3F29FB7D}
      RegDeleteKey HKCR\CLSID\{5A1C8180-2A52-470c-938C-BFB4E63AA32D}
      RegDeleteKey HKCR\CLSID\{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
      RegDeleteKey HKCR\CLSID\{647b8364-79e0-48e2-a4ca-233abada0c2d}
      RegDeleteKey HKCR\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
      RegDeleteKey HKCR\CLSID\{6F85DDE5-A2DE-4217-A05D-0A7CD3C04DC2}
      RegDeleteKey HKCR\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d}
      RegDeleteKey HKCR\CLSID\{72D597C4-2312-4116-BED4-4F9A2B2F710E}
      RegDeleteKey HKCR\CLSID\{77ca442a-0c72-492b-804a-82611e558142}
      RegDeleteKey HKCR\CLSID\{7e73c9db-69fb-4580-8e8e-194b34a2306c}
      RegDeleteKey HKCR\CLSID\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
      RegDeleteKey HKCR\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
      RegDeleteKey HKCR\CLSID\{861D5757-3A7E-4c46-966E-8CD53A0D0013}
      RegDeleteKey HKCR\CLSID\{8E3A1531-F462-4628-ADD8-D32984637641}
      RegDeleteKey HKCR\CLSID\{965a8d33-ae18-4c17-8011-fe42d81e0758}
      RegDeleteKey HKCR\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
      RegDeleteKey HKCR\CLSID\{9e87077c-380c-407d-8dab-eedad95c0a5d}
      RegDeleteKey HKCR\CLSID\{9F3D2A3C-D537-482b-A91B-44EE29F09C4B}
      RegDeleteKey HKCR\CLSID\{A99498D2-56E1-4e27-AC88-2328C6A87C7C}
      RegDeleteKey HKCR\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
      RegDeleteKey HKCR\CLSID\{ABC72615-4FB0-4689-AED9-AA6B89CEBC2C}
      RegDeleteKey HKCR\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
      RegDeleteKey HKCR\CLSID\{B296F12B-48A9-45fb-A860-4B98707B47AE}
      RegDeleteKey HKCR\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
      RegDeleteKey HKCR\CLSID\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
      RegDeleteKey HKCR\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
      RegDeleteKey HKCR\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
      RegDeleteKey HKCR\CLSID\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
      RegDeleteKey HKCR\CLSID\{B8CA1E6C-87E2-4435-9E56-8B791EC459D8}
      RegDeleteKey HKCR\CLSID\{c033567c-68fe-419b-bcc4-135db7faf8eb}
      RegDeleteKey HKCR\CLSID\{C08FA317-C152-4fea-AC0B-2EA68D2B1C84}
      RegDeleteKey HKCR\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
      RegDeleteKey HKCR\CLSID\{C427B3E3-28DC-4001-9590-D99B6776119B}
      RegDeleteKey HKCR\CLSID\{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
      RegDeleteKey HKCR\CLSID\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
      RegDeleteKey HKCR\CLSID\{ccaabcdd-7c16-4215-b12e-150bfb994cf0}
      RegDeleteKey HKCR\CLSID\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
      RegDeleteKey HKCR\CLSID\{e73e3959-fb15-44d7-acb9-3a75377006fc}
      RegDeleteKey HKCR\CLSID\{EAB5DB02-08F5-4e7d-81F9-75B9462FAAE3}
      RegDeleteKey HKCR\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
      RegDeleteKey HKCR\CLSID\{F0ED6398-E5F8-4ef8-BAB9-FE9BBCE7EF3E}
      RegDeleteKey HKCR\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
      RegDeleteKey HKCR\CLSID\{f63e3b76-f82f-46eb-851c-8c0a221686bb}
      RegDeleteKey HKCR\CLSID\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

      RegDeleteKey HKCR\Interface\{08C71FB1-1E66-4D22-9F32-4C045A451306}
      RegDeleteKey HKCR\Interface\{02946fd1-2d99-46e6-a790-3a089714edd9}
      RegDeleteKey HKCR\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442}
      RegDeleteKey HKCR\Interface\{1CE1C25B-F8B4-4974-99D2-5D4AE96B9900}
      RegDeleteKey HKCR\Interface\{35096C29-3507-4ABE-B6D8-C7CC881BE020}
      RegDeleteKey HKCR\Interface\{38F743A2-210F-49DE-9B79-DCD501CED284}
      RegDeleteKey HKCR\Interface\{3EEC290D-FC13-4C83-803D-4802651EEB61}
      RegDeleteKey HKCR\Interface\{41A5BBF6-3C9D-4CF9-9A99-32DD37CC290B}
      RegDeleteKey HKCR\Interface\{4E4F38D9-8736-41AE-B192-E829AE194398}
      RegDeleteKey HKCR\Interface\{4F79D1C5-24F9-4E59-8022-604D4B41D5CA}
      RegDeleteKey HKCR\Interface\{66484903-09F4-4330-927D-1F6C214221AC}
      RegDeleteKey HKCR\Interface\{7FA14AD6-D8E5-465F-9BD1-A37E26C1A74F}
      RegDeleteKey HKCR\Interface\{9E984934-CD94-4763-9DBC-618E483D4B7F}
      RegDeleteKey HKCR\Interface\{B115BD8E-B008-46F4-B8B6-3405EB325C3C}
      RegDeleteKey HKCR\Interface\{B9DFCF32-B679-4CAD-B7FC-518A48CE3922}
      RegDeleteKey HKCR\Interface\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
      RegDeleteKey HKCR\Interface\{CBEEF194-EBC5-4758-9B51-AC34FC135E70}
      RegDeleteKey HKCR\Interface\{CD3604CC-2B95-43EE-AFC9-E7444C21BE1C}
      RegDeleteKey HKCR\Interface\{D21040FE-0A57-4FAB-8ED2-F0E653E55809}
      RegDeleteKey HKCR\Interface\{D7A2488E-53E4-4EDD-AEAA-F24778BEB100}
      RegDeleteKey HKCR\Interface\{D7A6DF8D-B6CF-4C27-8E99-ECA2CE370EA7}
      RegDeleteKey HKCR\Interface\{e18b69d0-7e9e-4c6e-bdd8-879a1fff7123}
      RegDeleteKey HKCR\Interface\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
      RegDeleteKey HKCR\Interface\{F6C1582E-B11C-4724-B8F6-240457EF1D2A}
      RegDeleteKey HKCR\Interface\{FB787D5E-0C7C-4BAB-B45D-20325FB886DB}
      RegDeleteKey HKCR\Interface\{24F3E817-2C07-4CB5-975D-F23FCFAEDE51}
      RegDeleteKey HKCR\Interface\{3BB63444-FD94-4C31-9D6F-0DA76CB11D70}
      RegDeleteKey HKCR\Interface\{3C2656F4-8601-42B6-BDC3-DEC901E21C80}
      RegDeleteKey HKCR\Interface\{471D3AEF-F18C-4626-A7DB-320732ACC763}
      RegDeleteKey HKCR\Interface\{490E59CC-F6D5-4987-BBC8-E1A6D599C3F8}
      RegDeleteKey HKCR\Interface\{68A7506D-DF03-4DF0-BE96-02BCB918EA7D}
      RegDeleteKey HKCR\Interface\{74ECF6F4-62C5-48BA-945E-B20A97239A5E}
      RegDeleteKey HKCR\Interface\{7A66E632-E262-4986-A936-CC636282F138}
      RegDeleteKey HKCR\Interface\{7D9DFDB3-5135-4279-B365-3CEEA4AC1EAC}
      RegDeleteKey HKCR\Interface\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
      RegDeleteKey HKCR\Interface\{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
      RegDeleteKey HKCR\Interface\{81A7D75C-9768-41C3-AE0F-8B108D802B62}
      RegDeleteKey HKCR\Interface\{86786BEC-544D-473F-8D93-8E7AC0685361}
      RegDeleteKey HKCR\Interface\{92B92664-32D6-4FCE-B2CE-C8519BAEFC4E}
      RegDeleteKey HKCR\Interface\{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
      RegDeleteKey HKCR\Interface\{B0725565-2694-43EC-B1AB-0245762C9860}
      RegDeleteKey HKCR\Interface\{B26CA1F6-2D46-49AE-9897-9C5B7CCAB9FB}
      RegDeleteKey HKCR\Interface\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
      RegDeleteKey HKCR\Interface\{CADCB2CC-0B7E-45B1-A689-A0AD9CE5932D}
      RegDeleteKey HKCR\Interface\{D3390AE7-6F1D-464F-8921-AF9A85EED316}
      RegDeleteKey HKCR\Interface\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
      RegDeleteKey HKCR\Interface\{DB064061-95F1-4BAF-BEC9-F70792E01094}
      RegDeleteKey HKCR\Interface\{F3067DE7-3DBA-4DF8-9FA0-6B0200BAA324}
      RegDeleteKey HKCR\Interface\{f5ac8b35-5b15-4e8f-8046-43858973b495}
      RegDeleteKey HKCR\Interface\{FE899520-E9F9-4CD9-AABB-E9074815CF50}

      RegDeleteKey HKCR\TypeLib\{04392304-5221-4022-9300-be4128fb25b2}
      RegDeleteKey HKCR\TypeLib\{0E9F6AC0-A21A-4591-910F-E2C6F3CA094C}
      RegDeleteKey HKCR\TypeLib\{1234890a-5e6e-4867-8136-ca6f1456b235}
      RegDeleteKey HKCR\TypeLib\{1b197c22-561f-455f-8511-35b1a45c5c9f}
      RegDeleteKey HKCR\TypeLib\{17E55F3A-20AB-4668-A75F-DC96377AE16C}
      RegDeleteKey HKCR\TypeLib\(205FF72E-CA67-11D5-99DD-444553540006)
      RegDeleteKey HKCR\TypeLib\{248FDD41-4E0A-4138-9086-6CF5D6FA8179}
      RegDeleteKey HKCR\TypeLib\{25BAE2A9-DF54-4927-AF6F-9963146D11D8}
      RegDeleteKey HKCR\TypeLib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276}
      RegDeleteKey HKCR\TypeLib\{30ED49A5-CA6C-4918-B5F3-5E6818C91D8B}
      RegDeleteKey HKCR\TypeLib\{367a86a5-d048-4785-86be-4e2706aafdd9}
      RegDeleteKey HKCR\TypeLib\{371EFE75-C183-4D0C-B8CD-2DFAFEEB34D7}
      RegDeleteKey HKCR\TypeLib\{49f9ffb5-514d-4b69-b31d-2ae5a7d30ae6}
      RegDeleteKey HKCR\TypeLib\{4DCEEA42-794D-4855-9ECC-20DCF5F4FEA7}
      RegDeleteKey HKCR\TypeLib\{5F638503-4F2E-48F8-9210-9865AF4AD020}
      RegDeleteKey HKCR\TypeLib\{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
      RegDeleteKey HKCR\TypeLib\{692ca430-32c8-470d-ba1f-7e15e21e7043}
      RegDeleteKey HKCR\TypeLib\{6A077841-5016-42C8-92C8-F2D6B865BCD1}
      RegDeleteKey HKCR\TypeLib\{6bd7e052-306e-497a-ad23-601bc6bfc305}
      RegDeleteKey HKCR\TypeLib\{6F9DB588-66C5-4904-A2C7-423961358E8C}
      RegDeleteKey HKCR\TypeLib\{732b6533-7f78-4c47-9c01-2979ba0829b9}
      RegDeleteKey HKCR\TypeLib\{77dc6558-60e0-4644-a3df-b31f29d113bd}
      RegDeleteKey HKCR\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
      RegDeleteKey HKCR\TypeLib\{8D67C4E4-AAD6-46A1-812F-D7D21BBB4624}
      RegDeleteKey HKCR\TypeLib\{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
      RegDeleteKey HKCR\TypeLib\{a73973ab-95a6-4abe-a046-de3bab2be448}
      RegDeleteKey HKCR\TypeLib\{AD70AC89-F460-4E7E-B5A5-7EAF7E207736}
      RegDeleteKey HKCR\TypeLib\{B6625280-8CD8-4632-97C0-83CEC12A49A3}
      RegDeleteKey HKCR\TypeLib\{D49C1A5F-26CF-482E-81EE-1D4C9B057BD2}
      RegDeleteKey HKCR\TypeLib\{F458ADAE-D53B-4859-B99F-9FA127791278}
      RegDeleteKey HKCR\TypeLib\{FC76A5B8-DB35-4F3E-8B9A-BF0EEA098D64}

      RegDeleteKey HKCU\Software\ErrorGuard
      RegDeleteKey HKCU\Software\errorsafe
      RegDeleteKey HKCU\Software\error safe free
      RegDeleteKey HKCU\Software\sysprotect free
      RegDeleteKey HKCU\Software\SystemDoctor 2006 Free
      RegDeleteKey HKCU\Software\WinAntiSpyware 2006 Scanner
      RegDeleteKey HKCU\Software\WinAntiVirus Pro 2006
      RegDeleteKey HKCU\Software\WinFixer 2005
      RegDeleteKey HKCU\Software\WinSoftware

      RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{205ff73b-ca67-11d5-99dd-444553540006}
      RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}

      RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SystemDoctor 2006 Unregistered

      RegDeleteKey HKLM\Software\DriveCleaner 2006 Free
      RegDeleteKey HKLM\Software\ErrorSafe
      RegDeleteKey HKLM\Software\Error Safe Free
      RegDeleteKey HKLM\Software\sysprotect
      RegDeleteKey HKLM\Software\SystemDoctor 2006 Free
      RegDeleteKey HKLM\Software\WinAntiSpyware 2006 Scanner
      RegDeleteKey HKLM\Software\winantivirus pro 2006
      RegDeleteKey HKLM\Software\WinSoftware

      RegDeleteKey HKLM\Software\Classes\checkprod.checkproduct
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.AppCleaner
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan.1
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner.1
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner\CLSID
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner.1
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner.1
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner
      RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner.1
      RegDeleteKey HKLM\Software\Classes\df_fixr.Fixer
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner.1
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan.1
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner.1
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner.1
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner.1
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner
      RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner.1
      RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer
      RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer.1
      RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate
      RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate.1
      RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper
      RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper.1
      RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore
      RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore.1
      RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine
      RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine.1
      RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck
      RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck.1
      RegDeleteKey HKLM\Software\Classes\FFWraper.FFEnginWrapr
      RegDeleteKey HKLM\Software\Classes\FixCor.MMFixCore
      RegDeleteKey HKLM\Software\Classes\FlFxr5.FlFixer5
      RegDeleteKey HKLM\Software\Classes\FlFxr10.FlFixer10
      RegDeleteKey HKLM\Software\Classes\MMFixCtrl.CoFixEngin2
      RegDeleteKey HKLM\Software\Classes\SystemDoctor.Free
      RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk
      RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk.1
      RegDeleteKey HKLM\Software\Classes\UDCShell
      RegDeleteKey HKLM\Software\Classes\UWAS6.UWAS6
      RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier
      RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier.1
      RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook
      RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook.1
      RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu
      RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu.1
      RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier
      RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier.1
      RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu
      RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu.1
      RegDeleteKey HKLM\Software\Classes\WASPChk.WASPChk

      RegDeleteKey HKLM\Software\Classes\*\shellex\ContextMenuHandlers\UDCShell

      RegDeleteKey HKLM\Software\Classes\AppID\{1C02CE6B-CC12-4ea1-B2D8-113F611F25C2}
      RegDeleteKey HKLM\Software\Classes\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
      RegDeleteKey HKLM\Software\Classes\AppID\{8A1E94DA-725D-4f64-B110-DB3F73ADB6F7}
      RegDeleteKey HKLM\Software\Classes\AppID\{E7E155EE-EEF2-46af-99B7-65F1269DC3CF}
      RegDeleteKey HKLM\Software\Classes\AppID\{EE10A303-0C60-4acb-A033-95A790FA4DCD}
      RegDeleteKey HKLM\Software\Classes\AppID\checkproduct2_1.dll

      RegDeleteKey HKLM\Software\Classes\CLSID\{_CLSID_WAShellExecuteCheck}
      RegDeleteKey HKLM\Software\Classes\CLSID\{05324ED1-05C0-4e3a-A34F-98BFC64426F5}
      RegDeleteKey HKLM\Software\Classes\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
      RegDeleteKey HKLM\Software\Classes\CLSID\{0D7DE254-2FBD-4C09-9077-3DC4A2DEBE9D}
      RegDeleteKey HKLM\Software\Classes\CLSID\{1230649B-B980-44A5-B259-9B09EBEA6331}
      RegDeleteKey HKLM\Software\Classes\CLSID\{1236DE55-EDED-4675-AF10-BA15EDDB4D7A}
      RegDeleteKey HKLM\Software\Classes\CLSID\{184B0A26-4C9C-4757-ABF5-4B6AF71F9A45}
      RegDeleteKey HKLM\Software\Classes\CLSID\{18A41B20-E519-47a1-B545-FFC200730E9B}
      RegDeleteKey HKLM\Software\Classes\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
      RegDeleteKey HKLM\Software\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4}
      RegDeleteKey HKLM\Software\Classes\CLSID\{22024DC7-D190-44ec-9D49-AEE5F244A466}
      RegDeleteKey HKLM\Software\Classes\CLSID\{250D1063-5414-4fb0-86D5-AABB7A5D7DA7}
      RegDeleteKey HKLM\Software\Classes\CLSID\{2B334C22-40CA-438f-913A-61A8105C4CCD}
      RegDeleteKey HKLM\Software\Classes\CLSID\{2BF3C5AD-F9EC-49d8-8568-D7DFFC77108B}
      RegDeleteKey HKLM\Software\Classes\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
      RegDeleteKey HKLM\Software\Classes\CLSID\{43DB73EB-4C90-4418-B6AD-10DB22016908}
      RegDeleteKey HKLM\Software\Classes\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
      RegDeleteKey HKLM\Software\Classes\CLSID\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
      RegDeleteKey HKLM\Software\Classes\CLSID\{4F4E2384-42AD-4fe4-B966-B6D50C7BF90A}
      RegDeleteKey HKLM\Software\Classes\CLSID\{5284AC2A-EF00-4750-9B82-B5B907D26536}
      RegDeleteKey HKLM\Software\Classes\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
      RegDeleteKey HKLM\Software\Classes\CLSID\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
      RegDeleteKey HKLM\Software\Classes\CLSID\{5D178DBE-C867-417f-8A4E-D5DEFA4CD4E7}
      RegDeleteKey HKLM\Software\Classes\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
      RegDeleteKey HKLM\Software\Classes\CLSID\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
      RegDeleteKey HKLM\Software\Classes\CLSID\{6C8416A2-2408-4f4d-8D26-EC9A07E8DC98}
      RegDeleteKey HKLM\Software\Classes\CLSID\{7D435027-F646-4bf9-B2C5-0EF4940D5CA2}
      RegDeleteKey HKLM\Software\Classes\CLSID\{7EC618F2-C506-4221-9F56-792B92BF762E}
      RegDeleteKey HKLM\Software\Classes\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
      RegDeleteKey HKLM\Software\Classes\CLSID\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
      RegDeleteKey HKLM\Software\Classes\CLSID\{9C102B96-4845-4756-991E-4F9294965536}
      RegDeleteKey HKLM\Software\Classes\CLSID\{9CB12DAD-32C7-4f34-9758-C9FDD26D4D22}
      RegDeleteKey HKLM\Software\Classes\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
      RegDeleteKey HKLM\Software\Classes\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
      RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B11}
      RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B22}
      RegDeleteKey HKLM\Software\Classes\CLSID\{AE84FF0C-BABD-4D91-92A1-AF75D2D02E6D}
      RegDeleteKey HKLM\Software\Classes\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
      RegDeleteKey HKLM\Software\Classes\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
      RegDeleteKey HKLM\Software\Classes\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
      RegDeleteKey HKLM\Software\Classes\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
      RegDeleteKey HKLM\Software\Classes\CLSID\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
      RegDeleteKey HKLM\Software\Classes\CLSID\{C3E2988E-1433-469d-BFC1-4080D131FE1A}
      RegDeleteKey HKLM\Software\Classes\CLSID\{C4C4786C-9861-46d2-BB63-AC782AB07046}
      RegDeleteKey HKLM\Software\Classes\CLSID\{C833A552-F5AF-4a7b-87B3-6EBDE0DB3B43}
      RegDeleteKey HKLM\Software\Classes\CLSID\{CF080118-CDA5-429d-A8BD-EC7ECA74663F}
      RegDeleteKey HKLM\Software\Classes\CLSID\{D3377825-230D-4a12-805C-132557FA1A8B}
      RegDeleteKey HKLM\Software\Classes\CLSID\{D7136B99-FC27-4DC1-8497-5444D49B426A}
      RegDeleteKey HKLM\Software\Classes\CLSID\{DD45A464-7763-43EE-A756-5F2C93B0CF5E}
      RegDeleteKey HKLM\Software\Classes\CLSID\{E4A3F67D-5237-43fa-B3F2-41C37C1204B9}
      RegDeleteKey HKLM\Software\Classes\CLSID\{E78EA05B-B6A7-4dc4-879D-444DCD224CB4}
      RegDeleteKey HKLM\Software\Classes\CLSID\{EDF78E1B-31A2-4c6e-AD40-0AFCD0D55263}
      RegDeleteKey HKLM\Software\Classes\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
      RegDeleteKey HKLM\Software\Classes\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
      RegDeleteKey HKLM\Software\Classes\CLSID\{F5AB293C-2E21-4441-9AD8-B3646EB26DF5}
      RegDeleteKey HKLM\Software\Classes\CLSID\{FDA9BFC7-4ECD-43a0-AC1E-2E7DDE0C81B0}
      RegDeleteKey HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\{7EC618F2-C506-4221-9F56-792B92BF762E}

      RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerUWAS
      RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerWAS
      RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\UDCShell

      RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerUWAS
      RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerWAS
      RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\UDCShell

      RegDeleteKey HKLM\Software\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9}
      RegDeleteKey HKLM\Software\Classes\Interface\{0D146B7F-FA35-465D-B716-BCBC1F9A92D3}
      RegDeleteKey HKLM\Software\Classes\Interface\{12813770-461E-4A9F-8C5B-C227A8E9FBE8}
      RegDeleteKey HKLM\Software\Classes\Interface\{1562D24E-F5BF-4BB4-AF4C-BBB610B62638}
      RegDeleteKey HKLM\Software\Classes\Interface\{1BEA1806-F5C7-4696-B0A0-26CFD6A958DD}
      RegDeleteKey HKLM\Software\Classes\Interface\{258E07A2-FF65-493B-B6BD-421A1F2992A3}
      RegDeleteKey HKLM\Software\Classes\Interface\{2A1647E8-3EC2-49FE-B632-E12D765FA0CC}
      RegDeleteKey HKLM\Software\Classes\Interface\{2DECFCC9-D910-4BAC-94B8-FC006827A60F}
      RegDeleteKey HKLM\Software\Classes\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
      RegDeleteKey HKLM\Software\Classes\Interface\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
      RegDeleteKey HKLM\Software\Classes\Interface\{4B6A7638-0999-4924-93B7-C5738E1BAEE1}
      RegDeleteKey HKLM\Software\Classes\Interface\{5585C185-B318-4072-A00D-8385F443AE07}
      RegDeleteKey HKLM\Software\Classes\Interface\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
      RegDeleteKey HKLM\Software\Classes\Interface\{622423BD-B825-4989-BA65-86D0B990D328}
      RegDeleteKey HKLM\Software\Classes\Interface\{6813BFFD-BE81-4613-B4E6-AA7ED0DA8659}
      RegDeleteKey HKLM\Software\Classes\Interface\{7516C86C-2F3D-4724-BD4E-1608F1BDAE12}
      RegDeleteKey HKLM\Software\Classes\Interface\{7CA36000-3320-49D1-BAD1-4C5169D4084A}
      RegDeleteKey HKLM\Software\Classes\Interface\{7E7A1949-5C0C-45F3-A106-34FE038493EF}
      RegDeleteKey HKLM\Software\Classes\Interface\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
      RegDeleteKey HKLM\Software\Classes\Interface\{8E0A02C1-974F-4379-BFD3-69FFB9E0659D}
      RegDeleteKey HKLM\Software\Classes\Interface\{9793B356-4337-44AC-9A22-DF6A7930602C}
      RegDeleteKey HKLM\Software\Classes\Interface\{A1DDDD67-64B2-4CAB-BE0B-E34F3F12AED0}
      RegDeleteKey HKLM\Software\Classes\Interface\{A22FBA1E-CAAF-4E45-8EFF-4A821AF03E69}
      RegDeleteKey HKLM\Software\Classes\Interface\{A56B6D30-FDE0-42A9-BE6B-18B5D3F2F519}
      RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95411}
      RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95422}
      RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42611}
      RegDeleteKey HKLM\Software\Classes\Interface\{A0E2E5AB-C02F-489B-BD7B-58C329F774F3}
      RegDeleteKey HKLM\Software\Classes\Interface\{A6E398B2-A288-4D76-B0D0-8F153D14B66E}
      RegDeleteKey HKLM\Software\Classes\Interface\{A92616B1-2E82-4052-B579-0A40C2304380}
      RegDeleteKey HKLM\Software\Classes\Interface\{B22EE952-9A58-4495-AE78-C0146FA1A3C7}
      RegDeleteKey HKLM\Software\Classes\Interface\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
      RegDeleteKey HKLM\Software\Classes\Interface\{C3896A1E-8ECD-490B-8A1C-39FE9F7D64A1}
      RegDeleteKey HKLM\Software\Classes\Interface\{C88B2356-A6FE-41EC-B0FB-41F2C82C867E}
      RegDeleteKey HKLM\Software\Classes\Interface\{CF5C9FCE-C963-49E5-A3A4-0A81FFFE1E55}
      RegDeleteKey HKLM\Software\Classes\Interface\{D090E12D-B79C-4B82-A76C-0E3BBE73C9EF}
      RegDeleteKey HKLM\Software\Classes\Interface\{D7136B99-FC27-4DC1-8497-5444D49B426A}
      RegDeleteKey HKLM\Software\Classes\Interface\{D80A56D7-451C-41CF-9A74-1447E0887B97}
      RegDeleteKey HKLM\Software\Classes\Interface\{DE3C77B8-7378-4A4C-B6F8-4A008B4A6009}
      RegDeleteKey HKLM\Software\Classes\Interface\{E0110779-5F79-4685-9C96-9D99EFD30CA2}
      RegDeleteKey HKLM\Software\Classes\Interface\{E7CCBD19-2EEA-4B6A-B9BE-E8A68613809C}
      RegDeleteKey HKLM\Software\Classes\Interface\{E95F8133-A554-4C0C-9B9A-EEEE3B82CEDE}
      RegDeleteKey HKLM\Software\Classes\Interface\{EA0F107F-2BF6-44A0-96C4-A99B74AFBC4A}
      RegDeleteKey HKLM\Software\Classes\Interface\{F18701B3-185D-42FD-A55E-F47FDAC8F362}
      RegDeleteKey HKLM\Software\Classes\Interface\{F709F572-86F5-47C8-AFCF-3CEBC468FADB}
      RegDeleteKey HKLM\Software\Classes\Interface\{F97E5B38-4887-444A-86F5-91C18331500B}
      RegDeleteKey HKLM\Software\Classes\Interface\{F9AC5167-2C13-4607-B924-81C1C2251C84}
      RegDeleteKey HKLM\Software\Classes\Interface\{FB752175-36D8-4792-9302CFB8018C0DEC}

      RegDeleteKey HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\UDCShell

      RegDeleteKey HKLM\Software\Classes\SYSTEM\ControlSet003\Services\wasfsd

      RegDeleteKey HKLM\Software\Classes\TypeLib\{03A78DBD-AA12-4DB4-AB2C-564460D385DC}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{09AF1CF9-825C-4017-A7DC-088C68770F31}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{0A89FF7F-1A12-42D9-ACCB-4217112DC7E0}
      RegDeleteKey HKLM\software\classes\typelib\{1234890a-5e6e-4867-8136-ca6f1456b235}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{12398A44-7DFC-4C46-BD8F-41259D169A0D}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{16DEEE6B-AEFC-4BA6-9F32-57BBE6783A7C}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{21C724D0-B91A-4F35-99E7-55D325F00B20}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{223CEDCA-738B-4C4D-B8AE-C68B68C90A4A}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{5940CA88-8F1A-4A74-89E4-B3407E5E7348}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{61C1FC79-7120-4824-A563-D4D11D80BAFB}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{68BC55E9-4D3E-4C89-89AC-7559763C98B8}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{692CA430-32C8-470D-BA1F-7E15E21E7043}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{8ECC09E1-634B-42AC-8BE7-E6EDBB53C90E}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{A8C9AD38-7708-4BEB-A20C-B79614B4F120}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37411}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37422}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{B869788C-35DF-4104-BACB-8FDB83AFFFFD}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{BD9421BB-9F96-4272-802F-49BEC746056E}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{F874A0AE-66E8-426B-A3F5-6BA6958DCDBA}
      RegDeleteKey HKLM\Software\Classes\TypeLib\{FB42F450-C8B1-4799-99F1-87FA9CA92AB9}

      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\errorguard.exe

      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{205ff73b-ca67-11d5-99dd-444553540006}
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8C65AEF6-E413-4314-815B-82717A3F1603}
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3B4C621-6024-410B-9F0F-22CBD6981F5E}

      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Error Guard
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ERS_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ersu_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UDC6_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6V_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\usyp_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWFX_5_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWinFX6_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\wa6p_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WAS_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WFX5_is1
      RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAntiSpyware 2006 Scanner_is1

      RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sscan.sys
      RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sscan.sys

      RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\FOPN
      RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\uwasfsd
      RegDeleteKey HKLM\SYSTEM\ControlSet002\Services\FOPN

      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\df_km.sys
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ersd.sys
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sscan.sys

      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\df_kmd.sys
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ersd.sys
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sscan.sys

      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ERSD
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\enum\root\legacy_erssdd

      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\df_kmd
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\ersd
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\erssdd
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FOPN
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\uwasfsd
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
      RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\wasfsd

      RegDeleteKey HKUS\Software\DriveCleaner 2006 Free

      # 4 - ActiveX

      RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
      RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006}
      RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
      RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
      RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

      RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}|Compatibility Flags|1024
      RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{205FF73B-CA67-11D5-99DD-444553540006}|Compatibility Flags|1024
      RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}|Compatibility Flags|1024
      RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}|Compatibility Flags|1024
      RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{F919FBD3-A96B-4679-AF26-F551439BB5FD}|Compatibility Flags|1024

      # 5 - Fichiers

      DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCPChk.dll|1
      DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCShell.dll|1
      DllUnregister C:\Program Files\ErrorSafe\df_fixer.dll|1
      DllUnregister C:\Program Files\ErrorSafe\df_proxy.dll|1
      DllUnregister C:\Program Files\ErrorSafe\ecc.dll|1
      DllUnregister C:\Program Files\ErrorSafe\esSPCheck.dll|1
      DllUnregister C:\Program Files\ErrorSafe\FFWraper.dll|1
      DllUnregister C:\Program Files\ErrorSafe\FixCore.dll|1
      DllUnregister C:\Program Files\ErrorSafe\FiFxr5.dll|1
      DllUnregister C:\Program Files\ErrorSafe\FTRec.dll|1
      DllUnregister C:\Program Files\ErrorSafe\MMFix.dll|1
      DllUnregister C:\Program Files\ErrorSafe\StrRes.dll|1
      DllUnregister C:\Program Files\SysProtect\compclr.dll|1
      DllUnregister C:\Program Files\SysProtect\df_fixer.dll|1
      DllUnregister C:\Program Files\SysProtect\df_proxy.dll|1
      DllUnregister C:\Program Files\SysProtect\FFWrapr.dll|1
      DllUnregister C:\Program Files\SysProtect\flfxr10.dll|1
      DllUnregister C:\Program Files\SysProtect\FTRec.dll|1
      DllUnregister C:\Program Files\SysProtect\FxCore.dll|1
      DllUnregister C:\Program Files\SysProtect\MMFx.dll|1
      DllUnregister C:\Program Files\SysProtect\StrRes.dll|1
      DllUnregister C:\Program Files\SystemDoctor 2006 Free\order.dll|1
      DllUnregister C:\Program Files\VirusGarde\Addons\popupg.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006\AsAgents.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006\shellext.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\AsAgents.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\shellext.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\uwas6chk.dll|1
      DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\was6chk.dll|1
      DllUnregister C:\Program Files\WinAntiVirus Pro 2006\avkernel.dll|1
      DllUnregister C:\Program Files\WinAntiVirus Pro 2006\IEFWBHO.dll|1
      DllUnregister C:\Program Files\WinAntiVirus Pro 2006\libfn.dll|1
      DllUnregister C:\Program Files\WinAntiVirus Pro 2006\rpt.dll|1
      DllUnregister C:\Program Files\WinAntiVirus Pro 2006\winpgi.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\compcln.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\df_fixer.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\df_proxy.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\ffCom.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\FFWraper.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\FileTypeRecognizer.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\FixCore.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\MMFix.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\OEDrop.dll|1
      DllUnregister C:\Program Files\WinFixer 2005\StrRes.dll|1
      DllUnregister C:\Program Files\Common Files\Companion Wizard\WapCHK.dll|1
      DllUnregister C:\Program Files\Common Files\WinAntiSpyware 2006\was6chk.dll|1
      DllUnregister C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll|1
      DllUnregister C:\Program Files\Common Files\WinSoftware\CrXML.dll|1
      DllUnregister C:\Program Files\Common Files\WinSoftware\PCheck.dll|1
      DllUnregister C:\Program Files\Fichiers communs\WinFixer 2005\uwappchk.dll|1
      DllUnregister C:\WINDOWS\system32\SpOrder.dll|1
      DllUnregister C:\WINDOWS\syst32.dll|1

      FileDelete C:\Documents and Settings\All Users\Bureau\WinAntiVirus*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Application Data\*drivecleaner*.exe
      FileDelete C:\Documents and Settings\FLORENT\Application Data\*errorsafe*.exe
      FileDelete C:\Documents and Settings\FLORENT\Application Data\*winantispyware*.exe
      FileDelete C:\Documents and Settings\FLORENT\Application Data\*winantivirus*.exe
      FileDelete C:\Documents and Settings\FLORENT\Application Data\install_fr*.exe
      FileDelete C:\Documents and Settings\FLORENT\Application Data\Microsoft\Internet Explorer\Quick Launch\SystemDoctor*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Application Data\setup_fr[1].exe
      FileDelete C:\Documents and Settings\FLORENT\Bureau\*drivecleaner*.exe
      FileDelete C:\Documents and Settings\FLORENT\Bureau\DriveCleaner 2006 Free.lnk
      FileDelete C:\Documents and Settings\FLORENT\Bureau\ErrorGuard.lnk
      FileDelete C:\Documents and Settings\FLORENT\Bureau\ErrorSafe.lnk
      FileDelete C:\Documents and Settings\FLORENT\Bureau\ErrorSafe*.exe
      FileDelete C:\Documents and Settings\FLORENT\Bureau\SystemDoctor*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Bureau\WinAntiSpyware*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Bureau\WinFixer*.exe
      FileDelete C:\Documents and Settings\FLORENT\Bureau\WinFixer*.lnk
      FileDelete C:\Documents and Settings\FLORENT\Mes documents\*drivecleaner*.exe
      FileDelete C:\Documents and Settings\FLORENT\Mes documents\*SystemDoctor*.exe
      FileDelete C:\Documents and Settings\FLORENT\Mes documents\*WinAntiVirusPro*.exe
      FileDelete C:\Program Files\*drivecleaner*.exe
      FileDelete C:\Program Files\*WinAntiVirusPro*.exe
      FileDelete C:\Program Files\Common Files\Companion Wizard\compwiz.exe
      FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
      FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK{*}.dll
      FileDelete C:\WINDOWS\46241234110.exe
      FileDelete C:\WINDOWS\service32.exe
      FileDelete C:\WINDOWS\syst32.dll
      FileDelete C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.1\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.2\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.3\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.4\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.5\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.6\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.7\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.8\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.9\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.10\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.11\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.12\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.13\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.14\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.15\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.16\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.17\U*_*_*NetInstaller.exe
      FileDelete C:\WINDOWS\Prefetch\*winantispyware*.pf
      FileDelete C:\WINDOWS\system32\av.cpl
      FileDelete C:\WINDOWS\system32\df_kme.exe
      FileDelete C:\WINDOWS\system32\SpOrder.dll
      FileDelete C:\WINDOWS\system32\stera.exe
      FileDelete C:\WINDOWS\system32\stera.?o?
      FileDelete C:\WINDOWS\system32\drivers\ApiMon.sys
      FileDelete C:\WINDOWS\system32\drivers\df_kmd.sys
      FileDelete C:\WINDOWS\system32\drivers\ersd.sys
      FileDelete C:\WINDOWS\system32\drivers\erssdd.sys
      FileDelete C:\WINDOWS\system32\drivers\fopn.sys
      FileDelete C:\WINDOWS\system32\drivers\sscan.sys
      FileDelete C:\WINDOWS\system32\drivers\uwasfsd.sys
      FileDelete C:\WINDOWS\system32\drivers\vspf_hk5.sys
      FileDelete C:\WINDOWS\system32\drivers\vspf5.sys
      FileDelete C:\WINDOWS\system32\drivers\wasfsd.sys
      FileDelete C:\WINDOWS\system32\drivers\WFF.sys
      FileDelete C:\systemdoctor*.exe

      # 6 - Repertoires

      FolderDelete C:\Documents and Settings\FLORENT\Application Data\DriveCleaner Free
      FolderDelete C:\Documents and Settings\FLORENT\Application Data\systemdoctor 2006 free
      FolderDelete C:\Documents and Settings\FLORENT\Application Data\VirusGarde
      FolderDelete C:\Documents and Settings\FLORENT\Application Data\WinAntiVirus Pro 2006
      FolderDelete C:\Documents and Settings\FLORENT\Application Data\WinAntiVirus Pro 2007
      FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Corp
      FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
      FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DriveCleaner 2006 Free
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ErrorSafe
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\SystemDoctor 2006 Unregistered Version
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006 Scanner
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiVirus Pro 2006
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinFixer 2005
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\WinAntiVirus Pro 2007
      FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\SysProtect
      FolderDelete C:\Program Files\DriveCleaner 2006 Free
      FolderDelete C:\Program Files\erroguard
      FolderDelete C:\Program Files\Error Safe
      FolderDelete C:\Program Files\Error Safe Free
      FolderDelete C:\Program Files\ErrorSafe
      FolderDelete C:\Program Files\errorsafe free
      FolderDelete C:\Program Files\SysProtect Free
      FolderDelete C:\Program Files\SystemDoctor 2006
      FolderDelete C:\Program Files\SystemDoctor 2006 Free
      FolderDelete C:\Program Files\VirusGarde
      FolderDelete C:\Program Files\WinAntiSpyware 2006
      FolderDelete C:\Program Files\WinAntiSpyware 2006 Free
      FolderDelete C:\Program Files\WinAntiSpyware 2006 Scanner
      FolderDelete C:\Program Files\WinAntiVirus 2005
      FolderDelete C:\Program Files\WinAntiVirus Pro 2006
      FolderDelete C:\Program Files\WinAntiVirus Pro 2007
      FolderDelete C:\Program Files\WinFixer 2005
      FolderDelete C:\Program Files\WinPopupGuard 2005
      FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006
      FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006 Free
      FolderDelete C:\Program Files\Archivos comunes\DriveCleaner Free
      FolderDelete C:\Program Files\Archivos comunes\Error Safe
      FolderDelete C:\Program Files\Archivos comunes\erroguard
      FolderDelete C:\Program Files\Archivos comunes\errorguard
      FolderDelete C:\Program Files\Archivos comunes\ErrorSafe
      FolderDelete C:\Program Files\Archivos comunes\SystemDoctor
      FolderDelete C:\Program Files\Archivos comunes\SystemDoctor 2006
      FolderDelete C:\Program Files\Archivos comunes\WinAntiSpyware 2006
      FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2006
      FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2007
      FolderDelete C:\Program Files\Archivos comunes\WinFixer 2005
      FolderDelete C:\Program Files\Archivos comunes\WinSoftware
      FolderDelete C:\Program Files\Common Files\DriveCleaner 2006 Free
      FolderDelete C:\Program Files\Common Files\erroguard
      FolderDelete C:\Program Files\Common Files\errorguard
      FolderDelete C:\Program Files\Common Files\ErrorSafe
      FolderDelete C:\Program Files\Common Files\SysProtect
      FolderDelete C:\Program Files\Common Files\SystemDoctor 2006
      FolderDelete C:\Program Files\Common Files\WinAntiSpyware 2006
      FolderDelete C:\Program Files\Common Files\WinAntiVirus Pro 2006
      FolderDelete C:\Program Files\Common Files\WinFixer 2005
      FolderDelete C:\Program Files\Common Files\WinSoftware
      FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006
      FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006 Free
      FolderDelete C:\Program Files\Fichiers communs\DriveCleaner Free
      FolderDelete C:\Program Files\Fichiers communs\Error Safe
      FolderDelete C:\Program Files\Fichiers communs\erroguard
      FolderDelete C:\Program Files\Fichiers communs\errorguard
      FolderDelete C:\Program Files\Fichiers communs\ErrorSafe
      FolderDelete C:\Program Files\Fichiers communs\ProtectionAssuree
      FolderDelete C:\Program Files\Fichiers communs\SystemDoctor
      FolderDelete C:\Program Files\Fichiers communs\SystemDoctor 2006
      FolderDelete C:\Program Files\Fichiers communs\WinAntiSpyware 2006
      FolderDelete C:\Program Files\Fichiers communs\WinAntiVirus Pro 2006
      FolderDelete C:\Program Files\Fichiers communs\WinAntivirus Pro 2007
      FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
      FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
      FolderDelete C:\Program Files\Fichiers communs\WinSoftware
      FolderDelete C:\UWA7PV
      FolderDelete C:\WinAntiVirus Pro 2006

      # 7 - Nettoyage

      Filedelete %USERPROFILE%\Cookies\*@*drivecleaner*.txt
      Filedelete %USERPROFILE%\Cookies\*@*errorsafe*.txt
      Filedelete %USERPROFILE%\Cookies\*@*systemdoctor*.txt
      Filedelete %USERPROFILE%\Cookies\*@*WinAntiSpyware*.txt
      Filedelete %USERPROFILE%\Cookies\*@*winantivirus*.txt
      Filedelete %USERPROFILE%\Cookies\*@*winfixer*.txt
      Filedelete %USERPROFILE%\Cookies\*@*yieldmanager*.txt

      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\systemdoctor.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\win-anti-virus-pro.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispy.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantiviruspro.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfirewall.com|*|4
      RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com|*|4
      0
  12. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    rapport Hijackthis stp
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Le voici dsl je pensais l'avoir envoyé Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:58:28, on 09/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      C:\Program Files\Pack Securite\Anti-Virus\FSGK32.EXE
      C:\Program Files\Pack Securite\Common\FSMA32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fssm32.exe
      C:\Program Files\Pack Securite\Common\FSMB32.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Pack Securite\Common\FCH32.EXE
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Pack Securite\Common\FAMEH32.EXE
      C:\Program Files\Pack Securite\FSPC\fspc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsrw.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsav32.exe
      C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\WINDOWS\system32\pctspk.exe
      C:\Program Files\Apoint\Apoint.exe
      C:\WINDOWS\System32\DSentry.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Pack Securite\Common\FSM32.EXE
      C:\Program Files\Apoint\Apntex.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\PROGRA~1\PACKSE~1\ANTI-S~1\fsaw.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
      C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Pack Securite\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RTEGPRS] "C:\Program Files\Fichiers communs\RTE\RTEGPRS.exe" tray
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      O4 - Global Startup: Pack Securite.lnk = C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Pack Securite\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://m6video.m6.fr/1click/install/files/installer2.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
      O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/uploader/ImageUploader3.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/net/Import/ImageUploader3.cab
      O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab
      O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Pack Securite (BackWeb Plug-in - 361343) - BackWeb Technologies Inc. - C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Pack Securite\FSPC\fshttps\fshttps.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
  13. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    Lis bien et exécute cette manip dans l’ordre.

    #Télécharge et installe ces logiciels (si tu ne les as pas) pour les 3 premiers
    mets les à jour, comme indiqué dans les démos ou tutos.

    Ne les utilise pas tout de suite.

    Antispywares et autres :

    Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

    https://www.malwarebytes.com/

    A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

    Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

    Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

    MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.

    Nettoyeurs (de fichiers inutiles) et autres :

    *Ccleaner (gratuit)
    Téléchargement :
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    Tuto :
    https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

    Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

    ========================================
    ->Affiche tous les fichiers et dossiers :
    clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

    [Coche] « afficher les dossiers et fichiers cachés »

    [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

    [Décoche] « masquer les extensions dont le type est connu »

    Puis fais [appliquer] pour valider les changements.

    Et [Ok]
    .

    =======================================

    ->Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
    puis tape « entrée ».
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).

    ========================================
    ->Lance CCleaner.

    Suppression des fichiers temporaires

    Va dans la section "Options" situé dans la marge gauche.
    Décoche "Avancé"
    Retourne ensuite dans la section "Nettoyeur"
    Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
    • Clique sur [Analyse]
    • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
    • Une fois le scan terminé, clique sur [Lancer le Nettoyage]

    ========================================
    Lance Malwarebytes AntiMalware

    Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

    MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

    A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

    Si des malwares ont été détectés, leur liste s'affiche.
    En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

    MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

    Ferme MBAM en cliquant sur Quitter.
    ========================================

    ->Relance CCleaner.
    Suppression des incohérences du registre

    • Clique sur l'icône [Erreurs] situés dans la marge à gauche
    • Puis clique sur [Analyser les erreurs]
    • Patiente pendant que CCleaner scan ton registre.
    • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
    • Tu peux cliquer ensuite sur [Corriger les erreurs].

    Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
    ========================================
    ->Vide ta Corbeille.
    ========================================
    ->Redémarre en mode normal,

    - > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

    https://www.bitdefender.com/toolbox/

    Utilisation :
    Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et l'installer.
    Ensuite, cliquer sur "Cliquez ici pour scanner".
    Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

    Copier/coller le rapport entier sur le forum.

    Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)
    [Recoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

    Relance Hijackthis et copie/colle un nouveau rapport sur le forum.

    Et dis moi ou en sont tes problèmes s’il t’en reste.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      Bonsoir et désolée de ne pas t'avoir contacté plus tot j'ai du m'abstenté pour pblm perso....j'ai effectuer tes dernieres directives et voici le rapport BitDefender Online Scanner



      Scan report generated at: Mon, Apr 14, 2008 - 21:12:32





      Scan path: C:\;D:\;







      Statistics

      Time
      06:26:22

      Files
      325514

      Folders
      9437

      Boot Sectors
      3

      Archives
      9127

      Packed Files
      17255




      Results

      Identified Viruses
      18

      Infected Files
      25

      Suspect Files
      0

      Warnings
      0

      Disinfected
      0

      Deleted Files
      30




      Engines Info

      Virus Definitions
      1142452

      Engine build
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Scan plugins
      16

      Archive plugins
      41

      Unpack plugins
      7

      E-mail plugins
      6

      System plugins
      5




      Scan Settings

      First Action
      Disinfect

      Second Action
      Delete

      Heuristics
      Yes

      Enable Warnings
      Yes

      Scanned Extensions
      *;

      Exclude Extensions


      Scan Emails
      Yes

      Scan Archives
      Yes

      Scan Packed
      Yes

      Scan Files
      Yes

      Scan Boot
      Yes




      Scanned File
      Status

      C:\Documents and Settings\CHRYSTELLE\Application Data\errorsafefrenchnewreleaseinstall[1].exe
      Infected with: Trojan.Downloader.Winfixer.O

      C:\Documents and Settings\CHRYSTELLE\Application Data\errorsafefrenchnewreleaseinstall[1].exe
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Application Data\errorsafescannerinstall_fr[1].exe.xpx=>(Quarantine-PE)
      Infected with: Trojan.Downloader.Winfixer.O

      C:\Documents and Settings\CHRYSTELLE\Application Data\errorsafescannerinstall_fr[1].exe.xpx=>(Quarantine-PE)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Application Data\winantiviruspro2006freeinstall_fr[1].exe.xpx=>(Quarantine-PE)
      Infected with: Trojan.Downloader.Winfixer.O

      C:\Documents and Settings\CHRYSTELLE\Application Data\winantiviruspro2006freeinstall_fr[1].exe.xpx=>(Quarantine-PE)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\cd12B.tmp.exe
      Detected with: Adware.Hotbar.DR

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\cd12B.tmp.exe
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 3)
      Infected with: Trojan.Rkit.Agen.Af.2.B

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 3)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 4)
      Detected with: Adware.Errorsafe.J

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 4)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 7)
      Detected with: Adware.Errorsafe.G

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 7)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 8)
      Detected with: Application.Winfixer.DI

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 8)
      Disinfection failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 8)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 9)
      Detected with: Adware.Errorsafe.E

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 9)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 10)
      Detected with: Adware.Winfixer

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 10)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 11)
      Detected with: Adware.Errorsafe.J

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 11)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 16)
      Detected with: Adware.Errorsafe.B

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)=>(Instyler Module 16)
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\ErrorSafeScannerSetup.exe=>(Instyler o)
      Update failed

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\pack.epk=>(NSIS 2g)=>lzma_solid_nsis0007
      Detected with: Adware.SpywareSecure.D

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\pack.epk=>(NSIS 2g)=>lzma_solid_nsis0007
      Deleted

      C:\Documents and Settings\CHRYSTELLE\Local Settings\Temp\pack.epk=>(NSIS 2g)
      Update failed

      C:\Documents and Settings\FLORENT\Mes documents\My eBooks\Instant-Access.exe
      Detected with: Dialer.Instantaccess.AF

      C:\Documents and Settings\FLORENT\Mes documents\My eBooks\Instant-Access.exe
      Disinfection failed

      C:\Documents and Settings\FLORENT\Mes documents\My eBooks\Instant-Access.exe
      Deleted

      C:\Downloads\bgpackSetup-dm[1].exe
      Detected with: Adware.Trymedia.B.2

      C:\Downloads\bgpackSetup-dm[1].exe
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP491\A0240844.exe
      Detected with: Application.Zapspot.A

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP491\A0240844.exe
      Disinfection failed

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP491\A0240844.exe
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP491\A0240845.exe
      Detected with: Adware.Pehpai.C

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP491\A0240845.exe
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP493\A0240912.exe
      Detected with: Application.Powerreg.Scheduler.C

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP493\A0240912.exe
      Disinfection failed

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP493\A0240912.exe
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP499\A0243038.sys
      Detected with: Application.Winfixer.DQ

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP499\A0243038.sys
      Disinfection failed

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP499\A0243038.sys
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP502\A0243417.exe
      Infected with: Trojan.Downloader.Winfixer.O

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP502\A0243417.exe
      Deleted

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP502\A0243424.exe
      Detected with: Adware.Trymedia.B.2

      C:\System Volume Information\_restore{2D081E92-40B0-4D11-86A6-AF667022EB05}\RP502\A0243424.exe
      Deleted

      C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6PV_0001_N91M2107NetInstaller.exe.xpx=>(Quarantine-PE)
      Infected with: Trojan.Downloader.Winfixer.O

      C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6PV_0001_N91M2107NetInstaller.exe.xpx=>(Quarantine-PE)
      Deleted

      C:\WINDOWS\Downloaded Program Files\installer2.dll
      Detected with: Adware.Clickmedia.A

      C:\WINDOWS\Downloaded Program Files\installer2.dll
      Deleted

      C:\WINDOWS\Downloaded Program Files\UWA6PV_0001_N91M2107NetInstaller.exe.xpx=>(Quarantine-PE)
      Infected with: Trojan.Downloader.Winfixer.O

      C:\WINDOWS\Downloaded Program Files\UWA6PV_0001_N91M2107NetInstaller.exe.xpx=>(Quarantine-PE)
      Deleted

      C:\WINDOWS\SYSTEM32\zvrxoq.exe.xpx=>(Quarantine-PE)
      Detected with: Adware.Navipromo.BYT

      C:\WINDOWS\SYSTEM32\zvrxoq.exe.xpx=>(Quarantine-PE)
      Disinfection failed

      C:\WINDOWS\SYSTEM32\zvrxoq.exe.xpx=>(Quarantine-PE)
      Deleted





      de BitDefender je t'envoi u, autre message avec le rapport de Hijackthis
      0
    2. stella69200 Messages postés 16 Statut Membre
       
      Re voici dons le dernier rapport A l'heur actuelle je n'ai plus de CID milles merci et juste une derniere question puis désinstaller tous ce que tu m'as fait inLogfile of Trend Micro HijackThis v2.0.2
      Scan saved at 22:42:43, on 14/04/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      C:\Program Files\Pack Securite\Anti-Virus\FSGK32.EXE
      C:\Program Files\Pack Securite\Common\FSMA32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fssm32.exe
      C:\Program Files\Pack Securite\Common\FSMB32.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Pack Securite\Common\FCH32.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Pack Securite\Common\FAMEH32.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fsrw.exe
      C:\Program Files\Pack Securite\FSPC\fspc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Pack Securite\Anti-Virus\fsav32.exe
      C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      C:\WINDOWS\system32\pctspk.exe
      C:\Program Files\Apoint\Apoint.exe
      C:\WINDOWS\System32\DSentry.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Pack Securite\Common\FSM32.EXE
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      C:\PROGRA~1\PACKSE~1\ANTI-S~1\fsaw.exe
      C:\Program Files\Apoint\Apntex.exe
      C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
      C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Pack Securite\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [RTEGPRS] "C:\Program Files\Fichiers communs\RTE\RTEGPRS.exe" tray
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      O4 - Global Startup: Pack Securite.lnk = C:\Program Files\Pack Securite\backweb\361343\Program\fspex.exe
      O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Pack Securite\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra 'Tools' menuitem: Filtre Web - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\Anti-Spyware\ieshield.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
      O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://m6video.m6.fr/1click/install/files/installer2.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
      O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/uploader/ImageUploader3.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/net/Import/ImageUploader3.cab
      O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/zuma/oberongamesloader.cab
      O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Pack Securite (BackWeb Plug-in - 361343) - BackWeb Technologies Inc. - C:\PROGRA~1\PACKSE~1\backweb\361343\Program\SERVIC~1.EXE
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Pack Securite\backweb\361343\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Pack Securite\FSPC\fshttps\fshttps.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
  14. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonjour,

    je n'aime pas le rapport de bitdefender.

    Relance CCleaner, supprime les fichiers temporaires et relance un scan on line Bit defender et poste le rapport.
    0
    1. stella69200 Messages postés 16 Statut Membre
       
      RE j'ai un big probleme avec CCleaner car quand je fais l'analyse il m'affiche dans les fichiers temporaires des documents et programmes que je ne veux pas effacer(cv de mon mari,un programme qui est son outil de travail....)que dois je faire?
      0
  15. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    tu peux donner les noms de ces fichiers et les scanner avec ton antivirus ?
    0