Malwares et trojan trouvés par dizaines
lilyne
-
le douanier -
le douanier -
Bonjour,
Mon pc possede une cinquentaine de virus que j'ai petit a petit placés en quarantaine par peur d'endomger quelquechose. Le hic est que je ne suis pas tres forte en infrmatique et que je ne sais absolument pas quoi faire !
voici quelques noms de virus frequents sur mon pc:
- a.bat c:
- a0084927.exe dans c:\system volume infrmation\_restore-(BFF962A .....
- 2007rox.dll dans c:\WINOWS\System32
- audiohq.exe dans c:\WINOWS\System32
- avs.exe dans c:\documents ans settings\may\shared
- instaFinderK_inst.exe dans c:\WINDOWS\Temps\Adware
- norton.exe dans c:\
- nokrton.exe dams c:\
- netimon.exe dans c:\WINOWS\System
aidez moi svp ! merci
Mon pc possede une cinquentaine de virus que j'ai petit a petit placés en quarantaine par peur d'endomger quelquechose. Le hic est que je ne suis pas tres forte en infrmatique et que je ne sais absolument pas quoi faire !
voici quelques noms de virus frequents sur mon pc:
- a.bat c:
- a0084927.exe dans c:\system volume infrmation\_restore-(BFF962A .....
- 2007rox.dll dans c:\WINOWS\System32
- audiohq.exe dans c:\WINOWS\System32
- avs.exe dans c:\documents ans settings\may\shared
- instaFinderK_inst.exe dans c:\WINDOWS\Temps\Adware
- norton.exe dans c:\
- nokrton.exe dams c:\
- netimon.exe dans c:\WINOWS\System
aidez moi svp ! merci
A voir également:
- Malwares et trojan trouvés par dizaines
- Anti trojan - Télécharger - Antivirus & Antimalwares
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Trojan killer - Télécharger - Antivirus & Antimalwares
- Trojan sms-par google - Accueil - Messagerie instantanée
- Anti malwares - Télécharger - Antivirus & Antimalwares
3 réponses
salut a toi tu DOIS AVOIR NORTON COMME ANTIVIRUS CAR NORTON.EXE DANS TON LECTEUR C
SI TU VEUX CONNECTE TOI A CETTE ADRESSE HOTMAIL chlochar@hotail.fr ou installe spybot destroy 1.5 en francais sur telechager.com .ensuite il te fera le ménage sur ton pc.
SI TU VEUX CONNECTE TOI A CETTE ADRESSE HOTMAIL chlochar@hotail.fr ou installe spybot destroy 1.5 en francais sur telechager.com .ensuite il te fera le ménage sur ton pc.
voici le raport de hijackthis si ca peut t'aider.
que dois-je faire ?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.1.1.0/ImageUploader5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
voici le raport de hijackthis si ca peut t'aider.
que dois-je faire ?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.1.1.0/ImageUploader5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
puis-je tout effacer san pb?
--- Search result list ---
Zango: [SBI $C6989A30] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Zango Programs
Connect MFC Application: [SBI $82905A37] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\livesvc
Spyware-Secure: [SBI $7F4F2312] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\epk_extr
Winsoftware.WinAntiVirusPro2006: [SBI $854FBDDA] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vspf
Winsoftware.WinAntiVirusPro2006: [SBI $44AFF4D4] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vspf_hk
Winsoftware.WinAntiVirusPro2006: [SBI $26193B73] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vspf
Winsoftware.WinAntiVirusPro2006: [SBI $7DD75994] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vspf_hk
Winsoftware.WinAntiVirusPro2006: [SBI $47BE15AE] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Programas\WinAntiVirus Pro 2006\Updater.exe
Winsoftware.WinAntiVirusPro2006: [SBI $233BDB6D] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Programas\WinAntiVirus Pro 2006\Updater.exe
Winsoftware.WinAntiVirusPro2006: [SBI $9B8A2FDD] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\BootStera
Winsoftware.WinAntiVirusPro2006: [SBI $D4DD2B55] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\WinAntiVirus Pro 2006
Winsoftware.WinAntiVirusPro2006: [SBI $8C393191] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WAP6.PCheck
Winsoftware.WinAntiVirusPro2006: [SBI $8C393191] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WAP6.PCheck.1
Winsoftware.WinAntiVirusPro2006: [SBI $CAE82EFE] Groupe de programmes (Répertoire, nothing done)
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006\
Winsoftware.WinAntiVirusPro2006: [SBI $BCD551EA] Dossier Programme (Répertoire, nothing done)
C:\Documents and Settings\Mary\Application Data\WinAntiVirus Pro 2006\
Winsoftware.WinAntiVirusPro2006: [SBI $4741DE13] Dossier Programme (Répertoire, nothing done)
C:\Documents and Settings\Mary\Application Data\WinAntiVirus Pro 2006\Logs\
Accoona: [SBI $78EEA791] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Accoona
Accoona: [SBI $70CD72DA] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ABar.ABarBand
Accoona: [SBI $70CD72DA] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ABar.ABarBand.1
FunWebProducts: [SBI $561F0D2E] Réglages utilisateur (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\MenuExt\&Search\=...http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml...
FunWebProducts: [SBI $4BBFA8C4] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{38A7C9DA-8DB7-4D0F-A7B1-C4B1A305BDDB}
FunWebProducts: [SBI $0D974191] Bibliothèque (Fichier, nothing done)
C:\Programas\Internet Explorer\msimg32.dll
FunWebProducts: [SBI $BDA67685] Bibliothèque (Fichier, nothing done)
C:\Programas\Mozilla Firefox\plugins\NPMyWebS.dll
FunWebProducts: [SBI $7D9D33B1] Fichier de configuration (Fichier, nothing done)
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
FunWebProducts: [SBI $0B624DD2] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A6573479-9075-4A65-98A6-19FD29CF7374}
FunWebProducts: [SBI $9A8BE71B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D778513B-1C40-4819-B0C5-49E40B39AFD0}
FunWebProducts: [SBI $752F1D99] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayBarButton
FunWebProducts: [SBI $752F1D99] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayBarButton.1
FunWebProducts: [SBI $752F1D99] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D778513B-1C40-4819-B0C5-49E40B39AFD0}
FunWebProducts: [SBI $BB1A5557] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayEmbed
FunWebProducts: [SBI $BB1A5557] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayEmbed.1
FunWebProducts: [SBI $BB1A5557] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6573479-9075-4A65-98A6-19FD29CF7374}
FunWebProducts: [SBI $FE95534B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
FunWebProducts: [SBI $E56CA373] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
FunWebProducts: [SBI $F021587E] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.DataControl
FunWebProducts: [SBI $F021587E] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.DataControl.1
FunWebProducts: [SBI $F021587E] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
FunWebProducts: [SBI $8C4358AC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
FunWebProducts: [SBI $E3AF827A] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
FunWebProducts: [SBI $036600C0] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
FunWebProducts: [SBI $F146DAB4] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
FunWebProducts: [SBI $A3D08315] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
FunWebProducts: [SBI $3C959564] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
FunWebProducts: [SBI $78A60DD4] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340}
FunWebProducts: [SBI $C0B3D416] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.ShellViewControl
FunWebProducts: [SBI $C0B3D416] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.ShellViewControl.1
FunWebProducts: [SBI $C0B3D416] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340}
FunWebProducts: [SBI $47A9E7C5] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2763E333-B168-41A0-A112-D35F96F410C0}
FunWebProducts: [SBI $0563CE56] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{621FEACD-8857-43A6-AE26-451D670D5370}
FunWebProducts: [SBI $04BB720B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
FunWebProducts: [SBI $2AEC0692] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
FunWebProducts: [SBI $28AAB8CB] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
FunWebProducts: [SBI $9BCB8D2F] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
FunWebProducts: [SBI $61479453] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
FunWebProducts: [SBI $724750D4] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\ScreenSaver\
FunWebProducts: [SBI $A4654040] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\ScreenSaver\Images\
FunWebProducts: [SBI $E3B8EA3A] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
FunWebProducts: [SBI $5020B29C] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{8D292EC0-6792-4A38-82ED-73A087E41BA6}
FunWebProducts: [SBI $EA37F536] Réglages (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-f3embed
FunWebProducts: [SBI $EE3F6835] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{98635087-3F5D-418F-990C-B1EFE0797A3B}
FunWebProducts: [SBI $FA226905] Exécutable (Fichier, nothing done)
C:\WINDOWS\system32\f3PSSavr.scr
FunWebProducts: [SBI $BA1E7AA1] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
FunWebProducts: [SBI $7AEE25A5] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
FunWebProducts: [SBI $782F6C08] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
FunWebProducts: [SBI $4ED0CA01] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
FunWebProducts: [SBI $D4B80C31] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
FunWebProducts: [SBI $8CC75C5A] Réglages (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D}
FunWebProducts: [SBI $F3554FE5] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler
FunWebProducts: [SBI $F3554FE5] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler.1
FunWebProducts: [SBI $F3554FE5] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
FunWebProducts: [SBI $46DB56C2] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar
FunWebProducts: [SBI $46DB56C2] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar.1
FunWebProducts: [SBI $46DB56C2] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
FunWebProducts: [SBI $14E102B0] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.IECookiesManager
FunWebProducts: [SBI $14E102B0] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.IECookiesManager.1
FunWebProducts: [SBI $14E102B0] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
FunWebProducts: [SBI $F794F996] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.KillerObjManager
FunWebProducts: [SBI $F794F996] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.KillerObjManager.1
FunWebProducts: [SBI $F794F996] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
FunWebProducts: [SBI $B71E4FFD] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\
FunWebProducts: [SBI $E2D974B3] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Fun Web Products
MyWay.MyWebSearch: [SBI $17F9DD99] Réglages Autorun (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin
MyWay.MyWebSearch: [SBI $17F9DD99] Fichier de programme (Fichier, nothing done)
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
MyWay.MyWebSearch: [SBI $17F9DD99] Réglages Autorun (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin
MyWay.MyWebSearch: [SBI $31A33FBC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
MyWay.MyWebSearch: [SBI $45492A3B] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
MyWay.MyWebSearch: [SBI $C7B4FC73] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
MyWay.MyWebSearch: [SBI $A7E0CDDB] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin
MyWay.MyWebSearch: [SBI $A7E0CDDB] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin.1
MyWay.MyWebSearch: [SBI $A7E0CDDB] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
MyWay.MyWebSearch: [SBI $1EFB65ED] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
MyWay.MyWebSearch: [SBI $A9DBD3A1] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
MyWay.MyWebSearch: [SBI $B4140203] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
MyWay.MyWebSearch: [SBI $F1C75F59] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.HTMLPanel
MyWay.MyWebSearch: [SBI $F1C75F59] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.HTMLPanel.1
MyWay.MyWebSearch: [SBI $F1C75F59] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
MyWay.MyWebSearch: [SBI $8556DAFF] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
MyWay.MyWebSearch: [SBI $FE001122] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $74CCF0A1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin
MyWay.MyWebSearch: [SBI $74CCF0A1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin.1
MyWay.MyWebSearch: [SBI $74CCF0A1] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $7D166358] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $5B4611BE] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $4689C01C] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $39BC590A] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
MyWay.MyWebSearch: [SBI $D40B462F] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $4A61CD5B] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
MyWay.MyWebSearch: [SBI $6404C538] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $3EAEA461] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $9FB1BDFC] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
MyWay.MyWebSearch: [SBI $359D9C97] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
MyWay.MyWebSearch: [SBI $7390AC55] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
MyWay.MyWebSearch: [SBI $7B038A85] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin
MyWay.MyWebSearch: [SBI $7B038A85] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin.1
MyWay.MyWebSearch: [SBI $7B038A85] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
MyWay.MyWebSearch: [SBI $39E631BB] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
MyWay.MyWebSearch: [SBI $1D729FD1] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
MyWay.MyWebSearch: [SBI $8B97F486] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $B1C70274] Browser helper object (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\MyWebSearch
MyWay.MyWebSearch: [SBI $B70627CB] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
MyWay.MyWebSearch: [SBI $4991E2E9] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $BC537229] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $91B56C2A] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
MyWay.MyWebSearch: [SBI $C59FB266] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $5EE91522] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
MyWay.MyWebSearch: [SBI $8B1EDE10] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
MyWay.MyWebSearch: [SBI $80863035] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
MyWay.MyWebSearch: [SBI $39556604] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
MyWay.MyWebSearch: [SBI $8B82F326] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.OutlookAddin
MyWay.MyWebSearch: [SBI $8B82F326] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.OutlookAddin.1
MyWay.MyWebSearch: [SBI $8B82F326] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
MyWay.MyWebSearch: [SBI $21C50ADC] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin
MyWay.MyWebSearch: [SBI $21C50ADC] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin.1
MyWay.MyWebSearch: [SBI $21C50ADC] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $6D6DC0D4] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller
MyWay.MyWebSearch: [SBI $6D6DC0D4] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller.1
MyWay.MyWebSearch: [SBI $6D6DC0D4] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
MyWay.MyWebSearch: [SBI $8B993408] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
MyWay.MyWebSearch: [SBI $4C54BBA4] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
MyWay.MyWebSearch: [SBI $75BB5611] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
MyWay.MyWebSearch: [SBI $EABEA47E] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
MyWay.MyWebSearch: [SBI $95E7D650] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
MyWay.MyWebSearch: [SBI $DBE9DC78] Browser helper object (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\FocusInteractive
MyWay.MyWebSearch: [SBI $71059DE8] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
MyWay.MyWebSearch: [SBI $0AB712F8] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
MyWay.MyWebSearch: [SBI $6CDD369B] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
MyWay.MyWebSearch: [SBI $BDD40B52] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
MyWay.MyWebSearch: [SBI $5A6A799D] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
MyWay.MyWebSearch: [SBI $AC7657F9] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\MyWebSearch
MyWay.MyWebSearch: [SBI $BF485355] Barre d'outils IE (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $63E2271D] Barre d'outils IE (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
MyWay.MyWebSearch: [SBI $51E6ABA2] Dossier Programme (Répertoire, nothing done)
C:\Programas\MyWebSearch\
MyWay.MyWebSearch: [SBI $43FCC3D4] Browser helper object (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
Microsoft.WindowsSecurityCenter.AntiVirusOverride: [SBI $3604910C] Réglages (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride
Microsoft.WindowsSecurityCenter.FirewallOverride: [SBI $0C94D702] Réglages (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
Altnet: [SBI $2F41B249] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Altnet
Altnet: [SBI $6948D812] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM25.ADM25
Altnet: [SBI $6948D812] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM25.ADM25.1
Altnet: [SBI $B16AB920] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM4.ADM4
Altnet: [SBI $B16AB920] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM4.ADM4.1
Altnet: [SBI $383E5C9C] Donnée (Fichier, nothing done)
C:\WINDOWS\smdat32a.sys
Altnet: [SBI $3C8FED45] Dossier Programme (Répertoire, nothing done)
c:\Program Files\Altnet\
CommonName: [SBI $69E37531] Dossier temporaire (Répertoire, nothing done)
C:\WINDOWS\Temp\Adware
FunWeb: [SBI $0EC21589] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu
FunWeb: [SBI $0EC21589] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu.2
FunWeb: [SBI $0EC21589] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
FunWeb: [SBI $DC6264E6] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu.1
FunWeb: [SBI $DC6264E6] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
FunWeb: [SBI $A014255A] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton
FunWeb: [SBI $A014255A] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton.1
FunWeb: [SBI $A014255A] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
FunWeb: [SBI $AA287924] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl
FunWeb: [SBI $AA287924] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl.1
FunWeb: [SBI $AA287924] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
FunWeb: [SBI $DB2B49F5] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
FunWeb: [SBI $FD7B3B13] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
FunWeb: [SBI $C9EF9978] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Fun Web Products
FunWeb: [SBI $9FF1B3A4] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\FunWebProducts
FunWeb: [SBI $EABD1904] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts
Sumom.A: [SBI $319CF7B1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebP2PInstaller.Installer
Sumom.A: [SBI $319CF7B1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebP2PInstaller.Installer.1
Sumom.A: [SBI $95DB4DB6] Dossier Programme (Répertoire, nothing done)
C:\WINDOWS\system32\P2P Networking\
InstaFink: [SBI $0A3AD98F] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\INSTAFINK
InstaFink: [SBI $23959FC9] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\INSTAFINK
InstaFink: [SBI $AC29CC49] Groupe de programmes (Répertoire, nothing done)
C:\Programas\INSTAFINK\
MailSkinner.rtk: [SBI $165C0BCE] Dossier Programme (Répertoire, nothing done)
C:\Programas\MailSkinner\
MailSkinner.rtk: [SBI $4BEB9862] Image (Fichier, nothing done)
C:\Programas\MailSkinner\anim_0.gif
MailSkinner.rtk: [SBI $6A24156F] Dossier Programme (Répertoire, nothing done)
C:\WINDOWS\msskinner\
MailSkinner.rtk: [SBI $E7BB9E42] Donnée (Fichier, nothing done)
C:\WINDOWS\pack.epk
MailSkinner.rtk: [SBI $853E9584] Fichier texte (Fichier, nothing done)
C:\WINDOWS\Temp\msksetup.log
MailSkinner.rtk: [SBI $41F3194C] Réglages utilisateur (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\exts
MailSkinner.rtk: [SBI $20F4222F] Réglages utilisateur (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\mailskinner
MailSkinner.rtk: [SBI $B1C7D44F] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MailSkinner.exe
MailSkinner.rtk: [SBI $616623E3] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailSkinner
MessengerSkinner.rtk: [SBI $936304E8] Installeur (Fichier, nothing done)
C:\WINDOWS\system32\nvs2.inf
MyWebSearch: [SBI $0D15D009] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
MyWebSearch: [SBI $1BF07E2D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
MyWebSearch: [SBI $063FAF8F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
MyWebSearch: [SBI $49545C76] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
MyWebSearch: [SBI $4B220C13] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
MyWebSearch: [SBI $9BC10F0D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
MyWebSearch: [SBI $C497E5AD] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
MyWebSearch: [SBI $0778094F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
MyWebSearch: [SBI $A020D1EF] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
MyWebSearch: [SBI $4343368F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
MyWebSearch: [SBI $28E3F240] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
MyWebSearch: [SBI $EB0F98F9] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
MyWebSearch: [SBI $60D9B2FA] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
MyWebSearch: [SBI $134ADC4E] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
MyWebSearch: [SBI $7085932F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
MyWebSearch: [SBI $A352080D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
MyWebSearch: [SBI $689AB931] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
MyWebSearch: [SBI $1FBE02BC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
MyWebSearch: [SBI $FB21141E] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
MyWebSearch: [SBI $D197DEC0] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
MyWebSearch: [SBI $02ADCCBA] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
MyWebSearch: [SBI $2657A585] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\sources\f3PopularScreensavers
Win32.Bifrose.LA: [SBI $44EDC9AF] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Cn911
Win32.Bifrose.LA: [SBI $4B029FF4] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsmgmt
Win32.Bifrose.LA: [SBI $52A74310] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=...C:\WINDOWS\system32\secpol.exe,...
WinAntiVirusPro2006: [SBI $48113326] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\BootStera
WinAntiVirusPro2006: [SBI $C8D098E7] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootStera
WinAntiVirusPro2006: [SBI $488E01C8] Donnée (Fichier, nothing done)
C:\WINDOWS\system32\stera.job
BurstMedia: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
MediaPlex: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
Tradedoubler: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
Right Media: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
Adviva: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
Zedo: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
BlueStreak: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
BurstMedia: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
HitsLink: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
Statcounter: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
HitsLink: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
WebTrends live: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
MediaPlex: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
FastClick: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)
DoubleClick: Cookie traceur (Firefox: default) (Cookie, nothing done)
Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)
Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)
Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)
Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-05-15 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-04-16 Includes\Adware.sbi (*)
2008-05-14 Includes\AdwareC.sbi (*)
2008-05-14 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-05-14 Includes\DialerC.sbi (*)
2008-05-14 Includes\HeavyDuty.sbi (*)
2008-04-30 Includes\Hijackers.sbi (*)
2008-05-14 Includes\HijackersC.sbi (*)
2008-04-30 Includes\Keyloggers.sbi (*)
2008-05-14 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-04-22 Includes\Malware.sbi (*)
2008-05-14 Includes\MalwareC.sbi (*)
2008-03-26 Includes\PUPS.sbi (*)
2008-05-14 Includes\PUPSC.sbi (*)
2008-05-14 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-05-14 Includes\SecurityC.sbi (*)
2008-04-16 Includes\Spybots.sbi (*)
2008-05-14 Includes\SpybotsC.sbi (*)
2008-04-16 Includes\Spyware.sbi (*)
2008-05-14 Includes\SpywareC.sbi (*)
2007-11-06 Includes\Tracks.uti
2008-04-30 Includes\Trojans.sbi (*)
2008-05-14 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ Windows Media Player 10: Actualização de Segurança para o Windows Media Player 10 (KB917734)
/ Windows Media Player 6.4: Actualização de Segurança para o Windows Media Player 6.4 (KB925398)
/ Windows XP: Actualização de Segurança para Windows XP (KB923689)
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB893066)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Actualização para Windows XP (KB894391)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896358)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896422)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896423)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896424)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896428)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896688)
/ Windows XP / SP3: Actualização para Windows XP (KB898461)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899587)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899589)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899591)
/ Windows XP / SP3: Actualização para Windows XP (KB900485)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB900725)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB901017)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB901214)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB902400)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB904706)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905414)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905749)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905915)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB908519)
/ Windows XP / SP3: Actualização para Windows XP (KB908531)
/ Windows XP / SP3: Actualização para Windows XP (KB910437)
/ Windows XP / SP3: Actualização para Windows XP (KB911280)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911562)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911567)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911927)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB912812)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB912919)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB913446)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB913580)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB914388)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB914389)
/ Windows XP / SP3: Actualização para Windows XP (KB916595)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917159)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917344)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917422)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917953)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918118)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918439)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918899)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB919007)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920213)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920214)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920670)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920683)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920685)
/ Windows XP / SP3: Actualização para Windows XP (KB920872)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB921398)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB921883)
/ Windows XP / SP3: Actualização para Windows XP (KB922582)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB922616)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB922819)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923191)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923414)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923694)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923980)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924191)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924270)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924496)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924667)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925454)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925486)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925902)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB926255)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB926436)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB927779)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB927802)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928090)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928255)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928843)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB929969)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB930178)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB931261)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB931784)
/ Windows XP / SP3: Actualização para Windows XP (KB931836)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB932168)
--- Startup entries list ---
Located: HK_LM:Run,
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, AGRSMMSG
command: AGRSMMSG.exe
file: C:\WINDOWS\AGRSMMSG.exe
size: 88363
MD5: 0C7B4B167057E759083850F811005D1B
Located: HK_LM:Run, ATIModeChange
command: Ati2mdxx.exe
file: C:\WINDOWS\system32\Ati2mdxx.exe
size: 28672
MD5: FAE95D6D7651B5629C4E19ADBC9A3863
Located: HK_LM:Run, ATIPTA
command: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
file: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
size: 335872
MD5: C9989C1C9EEDE0F71C024F549E9C68E1
Located: HK_LM:Run, AudioHQ
command: "C:\WINDOWS\system32\audiohq.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 79224
MD5: E1E4780C87DACC69BE77DA4A1B3EC692
Located: HK_LM:Run, ClamWin
command: "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, MediaGateway
command: C:\Programas\MediaGateway\MediaGateway.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, Microsoft Works Update Detection
command: C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, Microsoft(R) System Manager
command: C:\WINDOWS\system32\sysmgr.exe
file: C:\WINDOWS\system32\sysmgr.exe
size: 54784
MD5: A7A9AD632060C8723F62B3DEB6113FE1
Located: HK_LM:Run, MMTray
command: MMTray.exe
file: C:\WINDOWS\system32\MMTray.exe
size: 53248
MD5: 3201FC905029F9760E77EF90B695D807
Located: HK_LM:Run, MMTray2K
command: MMTray2k.exe
file: C:\WINDOWS\system32\MMTray2k.exe
size: 57344
MD5: F2650F9F979436F70969FF8A2BAF320D
Located: HK_LM:Run, MMTrayLSI
command: MMTrayLSI.exe
file: C:\WINDOWS\system32\MMTrayLSI.exe
size: 53248
MD5: E391AB7127ACF2B82751F6C45BA9E956
Located: HK_LM:Run, My Web Search Bar
command: rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, MyWebSearch Email Plugin
command: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
file: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
size: 28672
MD5: DD59256AD65F4CDCA0BCE69216AE403B
Located: HK_LM:Run, NBKeyScan
command: "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, PRONoMgr.exe
command: C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
file: C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
size: 86016
MD5: 9F5DAB09F6E9B2C8D2D1092BE320FB7B
Located: HK_LM:Run, Regen
command: "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, snpstd
command: C:\WINDOWS\vsnpstd.exe
file: C:\WINDOWS\vsnpstd.exe
size: 286720
MD5: 09CE6B590FEF2CD6BB2BE540B1A26B89
Located: HK_LM:Run, SoundMan
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 577536
MD5: 80FD4D46B0E9B620CF757A9A5C789329
Located: HK_LM:Run, spywarefighterguard
command: D:\spftray.exe
file: D:\spftray.exe
size: 115344
MD5: A2F7E57E7878945D621194FC51C17798
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
file: C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
size: 144784
MD5: 836DC47E6CAD975304D1D3EB2F516A1C
Located: HK_LM:Run, TkBellExe
command: "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
file: C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
size: 180269
MD5: D09A5F5C4DBD5D4DFF09AB1A69812062
Located: HK_LM:Run, Windows Logon Application
command: C:\WINDOWS\system32\logon.exe
file: C:\WINDOWS\system32\logon.exe
size: 32768
MD5: D8622740DFF177FEE6698CBDFB101D5A
Located: HK_LM:RunOnce, Spybot - Search & Destroy
command: "D:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
file: D:\Spybot - Search & Destroy\SpybotSD.exe
size: 5146448
MD5: 2ECA8CDEED7C82F879E766DA92A3561A
Located: HK_LM:Run, AcctMgr (DISABLED)
command: C:\Programas\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, CplBCL50 (DISABLED)
command: C:\Programas\EzButton\CplBCL50.EXE
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, LtMoh (DISABLED)
command: C:\Programas\ltmoh\Ltmoh.exe
file: C:\Programas\ltmoh\Ltmoh.exe
size: 184320
MD5: EE364D07DB822E73B9ED058C22019AB9
Located: HK_LM:Run, SynTPEnh (DISABLED)
command: C:\Programas\Synaptics\SynTP\SynTPEnh.exe
file: C:\Programas\Synaptics\SynTP\SynTPEnh.exe
size: 491520
MD5: BBB2BD442C2BC9009E8BD35363A9A08C
Located: HK_LM:Run, SynTPLpr (DISABLED)
command: C:\Programas\Synaptics\SynTP\SynTPLpr.exe
file: C:\Programas\Synaptics\SynTP\SynTPLpr.exe
size: 98304
MD5: 86B7D4F76633535E128098E7B8F75941
Located: HK_CU:Run, ALUAlert
where: .DEFAULT...
command: C:\Programas\Symantec\LiveUpdate\ALUNotify.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, CTFMON.EXE
where: .DEFAULT...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:RunOnce, NeroHomeFirstStart
where: PE_C_ALL USERS...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMFirstStart.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, CTFMON.EXE
where: PE_C_CONVIDADO...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:Run, QuickTime Task
where: PE_C_CONVIDADO...
command: "C:\Programas\QuickTime\qttask.exe" -atboottime
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:RunOnce, NeroHomeFirstStart
where: PE_C_CONVIDADO...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMFirstStart.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, CTFMON.EXE
where: PE_C_MAMAN ET PAPA...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:Run, QuickTime Task
where: PE_C_MAMAN ET PAPA...
command: "C:\Programas\QuickTime\qttask.exe" -atboottime
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-19...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-20...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: HK_CU:Run, IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, MyWebSearch Email Plugin
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
file: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
size: 28672
MD5: DD59256AD65F4CDCA0BCE69216AE403B
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: D:\Spybot - Search & Destroy\TeaTimer.exe
file: D:\Spybot - Search & Destroy\TeaTimer.exe
size: 2097488
MD5: A9A5DB6AC3721BE698B996913693D73F
Located: HK_CU:Run, SweetIM
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\Programas\Macrogaming\SweetIM\SweetIM.exe
file: C:\Programas\Macrogaming\SweetIM\SweetIM.exe
size: 40960
MD5: 074F93E24502973FDA2ED859949435D5
Located: HK_CU:Run, ALUAlert
where: S-1-5-18...
command: C:\Programas\Symantec\LiveUpdate\ALUNotify.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-18...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF
Located: Démarrage (tous utilisateurs), AutoCAD Startup Accelerator.lnk
where: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque...
command: C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
file: C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
size: 10872
MD5: 9CBDBAF045D9572E3297E030820A21C1
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, fsmgmt
command: fsmgmt.dll
file: fsmgmt.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the check