Malwares et trojan trouvés par dizaines

lilyne -  
 le douanier -
Bonjour,
Mon pc possede une cinquentaine de virus que j'ai petit a petit placés en quarantaine par peur d'endomger quelquechose. Le hic est que je ne suis pas tres forte en infrmatique et que je ne sais absolument pas quoi faire !
voici quelques noms de virus frequents sur mon pc:

- a.bat c:
- a0084927.exe dans c:\system volume infrmation\_restore-(BFF962A .....
- 2007rox.dll dans c:\WINOWS\System32
- audiohq.exe dans c:\WINOWS\System32
- avs.exe dans c:\documents ans settings\may\shared
- instaFinderK_inst.exe dans c:\WINDOWS\Temps\Adware
- norton.exe dans c:\
- nokrton.exe dams c:\
- netimon.exe dans c:\WINOWS\System

aidez moi svp ! merci
A voir également:

3 réponses

le Douanier Messages postés 44 Statut Membre 3
 
salut a toi tu DOIS AVOIR NORTON COMME ANTIVIRUS CAR NORTON.EXE DANS TON LECTEUR C

SI TU VEUX CONNECTE TOI A CETTE ADRESSE HOTMAIL chlochar@hotail.fr ou installe spybot destroy 1.5 en francais sur telechager.com .ensuite il te fera le ménage sur ton pc.
0
lilyne
 
en effet j'avais norton mais je ne l'utilise plus depuis bien longtemps. desormais je possede avast.
voici le raport de hijackthis si ca peut t'aider.
que dois-je faire ?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.1.1.0/ImageUploader5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
0
lilyne
 
en effet j'avais norton mais je ne l'utilise plus depuis bien longtemps. desormais je possede avast.
voici le raport de hijackthis si ca peut t'aider.
que dois-je faire ?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:21, on 15-05-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RegSrvc.exe
c:\windows\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\msNTNSslog.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\MMTray.exe
C:\WINDOWS\system32\MMTray2k.exe
C:\WINDOWS\system32\MMTrayLSI.exe
C:\WINDOWS\vsnpstd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\sysmgr.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\WINDOWS\system32\logon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
D:\spftray.exe
D:\spfprc.exe
D:\SPYWAREfighter.exe
C:\WINDOWS\system32\freecell.exe
C:\Programas\Alwil Software\Avast4\ashChest.exe
C:\Programas\FreeCall.com\FreeCall\FreeCall.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Mary\Definições locais\Temporary Internet Files\Content.IE5\ARQ7E5CB\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pt/webhp?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\secpol.exe,
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programas\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Programas\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Programas\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programas\MyWebSearch\bar\2.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [MediaGateway] C:\Programas\MediaGateway\MediaGateway.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ClamWin] "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Regen] "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\sysmgr.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINDOWS\system32\logon.exe
O4 - HKLM\..\Run: [spywarefighterguard] D:\spftray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Programas\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Programas\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm451YYPT
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MBNet-Sidebar - {C014B140-3835-11d6-BC1D-00C095EEAD5D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} (MBNet) - https://www.mbnet.pt/sidebar/mbnetsidebar.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.1.1.0/ImageUploader5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDB6845C-00C0-4B24-BCEC-FAC7B9C946FF}: NameServer = 195.23.129.126,194.79.69.222
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: fsmgmt - C:\WINDOWS\SYSTEM32\fsmgmt.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: netimon - Unknown owner - C:\WINDOWS\system\netimon.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - D:\spfprc.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mary/DEFINI~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - http://www2.expresso.com.br/clientes/blogcarmen/presentenatal.gif
0
lilyne
 
voila le resultat de spybot
puis-je tout effacer san pb?






--- Search result list ---
Zango: [SBI $C6989A30] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Zango Programs

Connect MFC Application: [SBI $82905A37] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\livesvc

Spyware-Secure: [SBI $7F4F2312] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\epk_extr

Winsoftware.WinAntiVirusPro2006: [SBI $854FBDDA] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vspf

Winsoftware.WinAntiVirusPro2006: [SBI $44AFF4D4] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vspf_hk

Winsoftware.WinAntiVirusPro2006: [SBI $26193B73] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vspf

Winsoftware.WinAntiVirusPro2006: [SBI $7DD75994] Service Système (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vspf_hk

Winsoftware.WinAntiVirusPro2006: [SBI $47BE15AE] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Programas\WinAntiVirus Pro 2006\Updater.exe

Winsoftware.WinAntiVirusPro2006: [SBI $233BDB6D] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Programas\WinAntiVirus Pro 2006\Updater.exe

Winsoftware.WinAntiVirusPro2006: [SBI $9B8A2FDD] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\BootStera

Winsoftware.WinAntiVirusPro2006: [SBI $D4DD2B55] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\WinAntiVirus Pro 2006

Winsoftware.WinAntiVirusPro2006: [SBI $8C393191] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WAP6.PCheck

Winsoftware.WinAntiVirusPro2006: [SBI $8C393191] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WAP6.PCheck.1

Winsoftware.WinAntiVirusPro2006: [SBI $CAE82EFE] Groupe de programmes (Répertoire, nothing done)
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006\

Winsoftware.WinAntiVirusPro2006: [SBI $BCD551EA] Dossier Programme (Répertoire, nothing done)
C:\Documents and Settings\Mary\Application Data\WinAntiVirus Pro 2006\

Winsoftware.WinAntiVirusPro2006: [SBI $4741DE13] Dossier Programme (Répertoire, nothing done)
C:\Documents and Settings\Mary\Application Data\WinAntiVirus Pro 2006\Logs\

Accoona: [SBI $78EEA791] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Accoona

Accoona: [SBI $70CD72DA] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ABar.ABarBand

Accoona: [SBI $70CD72DA] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ABar.ABarBand.1

FunWebProducts: [SBI $561F0D2E] Réglages utilisateur (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\MenuExt\&Search\=...http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml...

FunWebProducts: [SBI $4BBFA8C4] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{38A7C9DA-8DB7-4D0F-A7B1-C4B1A305BDDB}

FunWebProducts: [SBI $0D974191] Bibliothèque (Fichier, nothing done)
C:\Programas\Internet Explorer\msimg32.dll

FunWebProducts: [SBI $BDA67685] Bibliothèque (Fichier, nothing done)
C:\Programas\Mozilla Firefox\plugins\NPMyWebS.dll

FunWebProducts: [SBI $7D9D33B1] Fichier de configuration (Fichier, nothing done)
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf

FunWebProducts: [SBI $0B624DD2] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A6573479-9075-4A65-98A6-19FD29CF7374}

FunWebProducts: [SBI $9A8BE71B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D778513B-1C40-4819-B0C5-49E40B39AFD0}

FunWebProducts: [SBI $752F1D99] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayBarButton

FunWebProducts: [SBI $752F1D99] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayBarButton.1

FunWebProducts: [SBI $752F1D99] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D778513B-1C40-4819-B0C5-49E40B39AFD0}

FunWebProducts: [SBI $BB1A5557] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayEmbed

FunWebProducts: [SBI $BB1A5557] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.BrowserOverlayEmbed.1

FunWebProducts: [SBI $BB1A5557] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6573479-9075-4A65-98A6-19FD29CF7374}

FunWebProducts: [SBI $FE95534B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}

FunWebProducts: [SBI $E56CA373] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}

FunWebProducts: [SBI $F021587E] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.DataControl

FunWebProducts: [SBI $F021587E] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.DataControl.1

FunWebProducts: [SBI $F021587E] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}

FunWebProducts: [SBI $8C4358AC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}

FunWebProducts: [SBI $E3AF827A] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728}

FunWebProducts: [SBI $036600C0] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}

FunWebProducts: [SBI $F146DAB4] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}

FunWebProducts: [SBI $A3D08315] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}

FunWebProducts: [SBI $3C959564] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}

FunWebProducts: [SBI $78A60DD4] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340}

FunWebProducts: [SBI $C0B3D416] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.ShellViewControl

FunWebProducts: [SBI $C0B3D416] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.ShellViewControl.1

FunWebProducts: [SBI $C0B3D416] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EFF3CF7-99C1-4c29-BC2B-68E057E22340}

FunWebProducts: [SBI $47A9E7C5] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2763E333-B168-41A0-A112-D35F96F410C0}

FunWebProducts: [SBI $0563CE56] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{621FEACD-8857-43A6-AE26-451D670D5370}

FunWebProducts: [SBI $04BB720B] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}

FunWebProducts: [SBI $2AEC0692] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}

FunWebProducts: [SBI $28AAB8CB] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}

FunWebProducts: [SBI $9BCB8D2F] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}

FunWebProducts: [SBI $61479453] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}

FunWebProducts: [SBI $724750D4] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\ScreenSaver\

FunWebProducts: [SBI $A4654040] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\ScreenSaver\Images\

FunWebProducts: [SBI $E3B8EA3A] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}

FunWebProducts: [SBI $5020B29C] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{8D292EC0-6792-4A38-82ED-73A087E41BA6}

FunWebProducts: [SBI $EA37F536] Réglages (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-f3embed

FunWebProducts: [SBI $EE3F6835] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{98635087-3F5D-418F-990C-B1EFE0797A3B}

FunWebProducts: [SBI $FA226905] Exécutable (Fichier, nothing done)
C:\WINDOWS\system32\f3PSSavr.scr

FunWebProducts: [SBI $BA1E7AA1] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

FunWebProducts: [SBI $7AEE25A5] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}

FunWebProducts: [SBI $782F6C08] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

FunWebProducts: [SBI $4ED0CA01] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

FunWebProducts: [SBI $D4B80C31] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

FunWebProducts: [SBI $8CC75C5A] Réglages (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D}

FunWebProducts: [SBI $F3554FE5] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler

FunWebProducts: [SBI $F3554FE5] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler.1

FunWebProducts: [SBI $F3554FE5] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

FunWebProducts: [SBI $46DB56C2] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar

FunWebProducts: [SBI $46DB56C2] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar.1

FunWebProducts: [SBI $46DB56C2] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

FunWebProducts: [SBI $14E102B0] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.IECookiesManager

FunWebProducts: [SBI $14E102B0] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.IECookiesManager.1

FunWebProducts: [SBI $14E102B0] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

FunWebProducts: [SBI $F794F996] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.KillerObjManager

FunWebProducts: [SBI $F794F996] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.KillerObjManager.1

FunWebProducts: [SBI $F794F996] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

FunWebProducts: [SBI $B71E4FFD] Dossier Programme (Répertoire, nothing done)
C:\Programas\FunWebProducts\

FunWebProducts: [SBI $E2D974B3] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Fun Web Products

MyWay.MyWebSearch: [SBI $17F9DD99] Réglages Autorun (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin

MyWay.MyWebSearch: [SBI $17F9DD99] Fichier de programme (Fichier, nothing done)
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

MyWay.MyWebSearch: [SBI $17F9DD99] Réglages Autorun (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin

MyWay.MyWebSearch: [SBI $31A33FBC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}

MyWay.MyWebSearch: [SBI $45492A3B] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}

MyWay.MyWebSearch: [SBI $C7B4FC73] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}

MyWay.MyWebSearch: [SBI $A7E0CDDB] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin

MyWay.MyWebSearch: [SBI $A7E0CDDB] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin.1

MyWay.MyWebSearch: [SBI $A7E0CDDB] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}

MyWay.MyWebSearch: [SBI $1EFB65ED] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}

MyWay.MyWebSearch: [SBI $A9DBD3A1] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}

MyWay.MyWebSearch: [SBI $B4140203] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906}

MyWay.MyWebSearch: [SBI $F1C75F59] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.HTMLPanel

MyWay.MyWebSearch: [SBI $F1C75F59] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.HTMLPanel.1

MyWay.MyWebSearch: [SBI $F1C75F59] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}

MyWay.MyWebSearch: [SBI $8556DAFF] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}

MyWay.MyWebSearch: [SBI $FE001122] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $74CCF0A1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin

MyWay.MyWebSearch: [SBI $74CCF0A1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin.1

MyWay.MyWebSearch: [SBI $74CCF0A1] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $7D166358] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $5B4611BE] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $4689C01C] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $39BC590A] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}

MyWay.MyWebSearch: [SBI $D40B462F] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $4A61CD5B] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}

MyWay.MyWebSearch: [SBI $6404C538] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $3EAEA461] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $9FB1BDFC] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}

MyWay.MyWebSearch: [SBI $359D9C97] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}

MyWay.MyWebSearch: [SBI $7390AC55] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}

MyWay.MyWebSearch: [SBI $7B038A85] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin

MyWay.MyWebSearch: [SBI $7B038A85] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin.1

MyWay.MyWebSearch: [SBI $7B038A85] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}

MyWay.MyWebSearch: [SBI $39E631BB] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}

MyWay.MyWebSearch: [SBI $1D729FD1] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}

MyWay.MyWebSearch: [SBI $8B97F486] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $B1C70274] Browser helper object (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\MyWebSearch

MyWay.MyWebSearch: [SBI $B70627CB] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}

MyWay.MyWebSearch: [SBI $4991E2E9] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $BC537229] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $91B56C2A] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}

MyWay.MyWebSearch: [SBI $C59FB266] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $5EE91522] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}

MyWay.MyWebSearch: [SBI $8B1EDE10] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

MyWay.MyWebSearch: [SBI $80863035] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}

MyWay.MyWebSearch: [SBI $39556604] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

MyWay.MyWebSearch: [SBI $8B82F326] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.OutlookAddin

MyWay.MyWebSearch: [SBI $8B82F326] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearch.OutlookAddin.1

MyWay.MyWebSearch: [SBI $8B82F326] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

MyWay.MyWebSearch: [SBI $21C50ADC] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin

MyWay.MyWebSearch: [SBI $21C50ADC] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin.1

MyWay.MyWebSearch: [SBI $21C50ADC] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $6D6DC0D4] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller

MyWay.MyWebSearch: [SBI $6D6DC0D4] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller.1

MyWay.MyWebSearch: [SBI $6D6DC0D4] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

MyWay.MyWebSearch: [SBI $8B993408] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}

MyWay.MyWebSearch: [SBI $4C54BBA4] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWay.MyWebSearch: [SBI $75BB5611] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}

MyWay.MyWebSearch: [SBI $EABEA47E] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}

MyWay.MyWebSearch: [SBI $95E7D650] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}

MyWay.MyWebSearch: [SBI $DBE9DC78] Browser helper object (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\FocusInteractive

MyWay.MyWebSearch: [SBI $71059DE8] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}

MyWay.MyWebSearch: [SBI $0AB712F8] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin

MyWay.MyWebSearch: [SBI $6CDD369B] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin

MyWay.MyWebSearch: [SBI $BDD40B52] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}

MyWay.MyWebSearch: [SBI $5A6A799D] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall

MyWay.MyWebSearch: [SBI $AC7657F9] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\MyWebSearch

MyWay.MyWebSearch: [SBI $BF485355] Barre d'outils IE (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $63E2271D] Barre d'outils IE (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

MyWay.MyWebSearch: [SBI $51E6ABA2] Dossier Programme (Répertoire, nothing done)
C:\Programas\MyWebSearch\

MyWay.MyWebSearch: [SBI $43FCC3D4] Browser helper object (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

Microsoft.WindowsSecurityCenter.AntiVirusOverride: [SBI $3604910C] Réglages (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride

Microsoft.WindowsSecurityCenter.FirewallOverride: [SBI $0C94D702] Réglages (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride

Altnet: [SBI $2F41B249] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Altnet

Altnet: [SBI $6948D812] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM25.ADM25

Altnet: [SBI $6948D812] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM25.ADM25.1

Altnet: [SBI $B16AB920] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM4.ADM4

Altnet: [SBI $B16AB920] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADM4.ADM4.1

Altnet: [SBI $383E5C9C] Donnée (Fichier, nothing done)
C:\WINDOWS\smdat32a.sys

Altnet: [SBI $3C8FED45] Dossier Programme (Répertoire, nothing done)
c:\Program Files\Altnet\

CommonName: [SBI $69E37531] Dossier temporaire (Répertoire, nothing done)
C:\WINDOWS\Temp\Adware

FunWeb: [SBI $0EC21589] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu

FunWeb: [SBI $0EC21589] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu.2

FunWeb: [SBI $0EC21589] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}

FunWeb: [SBI $DC6264E6] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.HTMLMenu.1

FunWeb: [SBI $DC6264E6] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}

FunWeb: [SBI $A014255A] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton

FunWeb: [SBI $A014255A] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton.1

FunWeb: [SBI $A014255A] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}

FunWeb: [SBI $AA287924] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl

FunWeb: [SBI $AA287924] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl.1

FunWeb: [SBI $AA287924] Class ID (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}

FunWeb: [SBI $DB2B49F5] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}

FunWeb: [SBI $FD7B3B13] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}

FunWeb: [SBI $C9EF9978] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Fun Web Products

FunWeb: [SBI $9FF1B3A4] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\FunWebProducts

FunWeb: [SBI $EABD1904] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts

Sumom.A: [SBI $319CF7B1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebP2PInstaller.Installer

Sumom.A: [SBI $319CF7B1] Root class (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WebP2PInstaller.Installer.1

Sumom.A: [SBI $95DB4DB6] Dossier Programme (Répertoire, nothing done)
C:\WINDOWS\system32\P2P Networking\

InstaFink: [SBI $0A3AD98F] Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\INSTAFINK

InstaFink: [SBI $23959FC9] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\INSTAFINK

InstaFink: [SBI $AC29CC49] Groupe de programmes (Répertoire, nothing done)
C:\Programas\INSTAFINK\

MailSkinner.rtk: [SBI $165C0BCE] Dossier Programme (Répertoire, nothing done)
C:\Programas\MailSkinner\

MailSkinner.rtk: [SBI $4BEB9862] Image (Fichier, nothing done)
C:\Programas\MailSkinner\anim_0.gif

MailSkinner.rtk: [SBI $6A24156F] Dossier Programme (Répertoire, nothing done)
C:\WINDOWS\msskinner\

MailSkinner.rtk: [SBI $E7BB9E42] Donnée (Fichier, nothing done)
C:\WINDOWS\pack.epk

MailSkinner.rtk: [SBI $853E9584] Fichier texte (Fichier, nothing done)
C:\WINDOWS\Temp\msksetup.log

MailSkinner.rtk: [SBI $41F3194C] Réglages utilisateur (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\exts

MailSkinner.rtk: [SBI $20F4222F] Réglages utilisateur (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1177238915-1202660629-1060284298-1003\Software\mailskinner

MailSkinner.rtk: [SBI $B1C7D44F] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MailSkinner.exe

MailSkinner.rtk: [SBI $616623E3] Réglages désinstallation (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailSkinner

MessengerSkinner.rtk: [SBI $936304E8] Installeur (Fichier, nothing done)
C:\WINDOWS\system32\nvs2.inf

MyWebSearch: [SBI $0D15D009] Class ID (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}

MyWebSearch: [SBI $1BF07E2D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}

MyWebSearch: [SBI $063FAF8F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}

MyWebSearch: [SBI $49545C76] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}

MyWebSearch: [SBI $4B220C13] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{120927BF-1700-43BC-810F-FAB92549B390}

MyWebSearch: [SBI $9BC10F0D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}

MyWebSearch: [SBI $C497E5AD] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}

MyWebSearch: [SBI $0778094F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}

MyWebSearch: [SBI $A020D1EF] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}

MyWebSearch: [SBI $4343368F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}

MyWebSearch: [SBI $28E3F240] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}

MyWebSearch: [SBI $EB0F98F9] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}

MyWebSearch: [SBI $60D9B2FA] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}

MyWebSearch: [SBI $134ADC4E] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}

MyWebSearch: [SBI $7085932F] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{991AAC62-B100-47CE-8B75-253965244F69}

MyWebSearch: [SBI $A352080D] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}

MyWebSearch: [SBI $689AB931] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}

MyWebSearch: [SBI $1FBE02BC] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}

MyWebSearch: [SBI $FB21141E] Interface (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}

MyWebSearch: [SBI $D197DEC0] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}

MyWebSearch: [SBI $02ADCCBA] Type library (Clé du registre, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}

MyWebSearch: [SBI $2657A585] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\sources\f3PopularScreensavers

Win32.Bifrose.LA: [SBI $44EDC9AF] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Cn911

Win32.Bifrose.LA: [SBI $4B029FF4] Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsmgmt

Win32.Bifrose.LA: [SBI $52A74310] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=...C:\WINDOWS\system32\secpol.exe,...

WinAntiVirusPro2006: [SBI $48113326] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\BootStera

WinAntiVirusPro2006: [SBI $C8D098E7] Réglages (Valeur du registre, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootStera

WinAntiVirusPro2006: [SBI $488E01C8] Donnée (Fichier, nothing done)
C:\WINDOWS\system32\stera.job

BurstMedia: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


MediaPlex: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


Tradedoubler: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


Right Media: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


Adviva: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


Zedo: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


BlueStreak: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


BurstMedia: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


HitsLink: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


Statcounter: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


HitsLink: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


WebTrends live: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


AdRevolver: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


MediaPlex: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


FastClick: Cookie traceur (Internet Explorer: Mary) (Cookie, nothing done)


DoubleClick: Cookie traceur (Firefox: default) (Cookie, nothing done)


Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)


Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)


Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)


Tradedoubler: Cookie traceur (Firefox: default) (Cookie, nothing done)



--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-05-15 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-04-16 Includes\Adware.sbi (*)
2008-05-14 Includes\AdwareC.sbi (*)
2008-05-14 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-05-14 Includes\DialerC.sbi (*)
2008-05-14 Includes\HeavyDuty.sbi (*)
2008-04-30 Includes\Hijackers.sbi (*)
2008-05-14 Includes\HijackersC.sbi (*)
2008-04-30 Includes\Keyloggers.sbi (*)
2008-05-14 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-04-22 Includes\Malware.sbi (*)
2008-05-14 Includes\MalwareC.sbi (*)
2008-03-26 Includes\PUPS.sbi (*)
2008-05-14 Includes\PUPSC.sbi (*)
2008-05-14 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-05-14 Includes\SecurityC.sbi (*)
2008-04-16 Includes\Spybots.sbi (*)
2008-05-14 Includes\SpybotsC.sbi (*)
2008-04-16 Includes\Spyware.sbi (*)
2008-05-14 Includes\SpywareC.sbi (*)
2007-11-06 Includes\Tracks.uti
2008-04-30 Includes\Trojans.sbi (*)
2008-05-14 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ Windows Media Player 10: Actualização de Segurança para o Windows Media Player 10 (KB917734)
/ Windows Media Player 6.4: Actualização de Segurança para o Windows Media Player 6.4 (KB925398)
/ Windows XP: Actualização de Segurança para Windows XP (KB923689)
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB893066)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Actualização para Windows XP (KB894391)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896358)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896422)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896423)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896424)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896428)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB896688)
/ Windows XP / SP3: Actualização para Windows XP (KB898461)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899587)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899589)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB899591)
/ Windows XP / SP3: Actualização para Windows XP (KB900485)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB900725)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB901017)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB901214)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB902400)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB904706)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905414)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905749)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB905915)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB908519)
/ Windows XP / SP3: Actualização para Windows XP (KB908531)
/ Windows XP / SP3: Actualização para Windows XP (KB910437)
/ Windows XP / SP3: Actualização para Windows XP (KB911280)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911562)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911567)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB911927)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB912812)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB912919)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB913446)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB913580)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB914388)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB914389)
/ Windows XP / SP3: Actualização para Windows XP (KB916595)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917159)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917344)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917422)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB917953)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918118)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918439)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB918899)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB919007)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920213)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920214)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920670)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920683)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB920685)
/ Windows XP / SP3: Actualização para Windows XP (KB920872)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB921398)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB921883)
/ Windows XP / SP3: Actualização para Windows XP (KB922582)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB922616)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB922819)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923191)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923414)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923694)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB923980)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924191)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924270)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924496)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB924667)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925454)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925486)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB925902)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB926255)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB926436)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB927779)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB927802)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928090)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928255)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB928843)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB929969)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB930178)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB931261)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB931784)
/ Windows XP / SP3: Actualização para Windows XP (KB931836)
/ Windows XP / SP3: Actualização de segurança para Windows XP (KB932168)


--- Startup entries list ---
Located: HK_LM:Run,
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, AGRSMMSG
command: AGRSMMSG.exe
file: C:\WINDOWS\AGRSMMSG.exe
size: 88363
MD5: 0C7B4B167057E759083850F811005D1B

Located: HK_LM:Run, ATIModeChange
command: Ati2mdxx.exe
file: C:\WINDOWS\system32\Ati2mdxx.exe
size: 28672
MD5: FAE95D6D7651B5629C4E19ADBC9A3863

Located: HK_LM:Run, ATIPTA
command: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
file: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
size: 335872
MD5: C9989C1C9EEDE0F71C024F549E9C68E1

Located: HK_LM:Run, AudioHQ
command: "C:\WINDOWS\system32\audiohq.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 79224
MD5: E1E4780C87DACC69BE77DA4A1B3EC692

Located: HK_LM:Run, ClamWin
command: "C:\Programas\ClamWin\bin\ClamTray.exe" --logon
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, MediaGateway
command: C:\Programas\MediaGateway\MediaGateway.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, Microsoft Works Update Detection
command: C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, Microsoft(R) System Manager
command: C:\WINDOWS\system32\sysmgr.exe
file: C:\WINDOWS\system32\sysmgr.exe
size: 54784
MD5: A7A9AD632060C8723F62B3DEB6113FE1

Located: HK_LM:Run, MMTray
command: MMTray.exe
file: C:\WINDOWS\system32\MMTray.exe
size: 53248
MD5: 3201FC905029F9760E77EF90B695D807

Located: HK_LM:Run, MMTray2K
command: MMTray2k.exe
file: C:\WINDOWS\system32\MMTray2k.exe
size: 57344
MD5: F2650F9F979436F70969FF8A2BAF320D

Located: HK_LM:Run, MMTrayLSI
command: MMTrayLSI.exe
file: C:\WINDOWS\system32\MMTrayLSI.exe
size: 53248
MD5: E391AB7127ACF2B82751F6C45BA9E956

Located: HK_LM:Run, My Web Search Bar
command: rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, MyWebSearch Email Plugin
command: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
file: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
size: 28672
MD5: DD59256AD65F4CDCA0BCE69216AE403B

Located: HK_LM:Run, NBKeyScan
command: "D:\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, PRONoMgr.exe
command: C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
file: C:\Programas\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
size: 86016
MD5: 9F5DAB09F6E9B2C8D2D1092BE320FB7B

Located: HK_LM:Run, Regen
command: "C:\Programas\OnSpec\All Users\Regen\Regen.exe" /STARTUP
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, snpstd
command: C:\WINDOWS\vsnpstd.exe
file: C:\WINDOWS\vsnpstd.exe
size: 286720
MD5: 09CE6B590FEF2CD6BB2BE540B1A26B89

Located: HK_LM:Run, SoundMan
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 577536
MD5: 80FD4D46B0E9B620CF757A9A5C789329

Located: HK_LM:Run, spywarefighterguard
command: D:\spftray.exe
file: D:\spftray.exe
size: 115344
MD5: A2F7E57E7878945D621194FC51C17798

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"
file: C:\Programas\Java\jre1.6.0_05\bin\jusched.exe
size: 144784
MD5: 836DC47E6CAD975304D1D3EB2F516A1C

Located: HK_LM:Run, TkBellExe
command: "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot
file: C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
size: 180269
MD5: D09A5F5C4DBD5D4DFF09AB1A69812062

Located: HK_LM:Run, Windows Logon Application
command: C:\WINDOWS\system32\logon.exe
file: C:\WINDOWS\system32\logon.exe
size: 32768
MD5: D8622740DFF177FEE6698CBDFB101D5A

Located: HK_LM:RunOnce, Spybot - Search & Destroy
command: "D:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
file: D:\Spybot - Search & Destroy\SpybotSD.exe
size: 5146448
MD5: 2ECA8CDEED7C82F879E766DA92A3561A

Located: HK_LM:Run, AcctMgr (DISABLED)
command: C:\Programas\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, CplBCL50 (DISABLED)
command: C:\Programas\EzButton\CplBCL50.EXE
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, LtMoh (DISABLED)
command: C:\Programas\ltmoh\Ltmoh.exe
file: C:\Programas\ltmoh\Ltmoh.exe
size: 184320
MD5: EE364D07DB822E73B9ED058C22019AB9

Located: HK_LM:Run, SynTPEnh (DISABLED)
command: C:\Programas\Synaptics\SynTP\SynTPEnh.exe
file: C:\Programas\Synaptics\SynTP\SynTPEnh.exe
size: 491520
MD5: BBB2BD442C2BC9009E8BD35363A9A08C

Located: HK_LM:Run, SynTPLpr (DISABLED)
command: C:\Programas\Synaptics\SynTP\SynTPLpr.exe
file: C:\Programas\Synaptics\SynTP\SynTPLpr.exe
size: 98304
MD5: 86B7D4F76633535E128098E7B8F75941

Located: HK_CU:Run, ALUAlert
where: .DEFAULT...
command: C:\Programas\Symantec\LiveUpdate\ALUNotify.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, CTFMON.EXE
where: .DEFAULT...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:RunOnce, NeroHomeFirstStart
where: PE_C_ALL USERS...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMFirstStart.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, CTFMON.EXE
where: PE_C_CONVIDADO...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:Run, QuickTime Task
where: PE_C_CONVIDADO...
command: "C:\Programas\QuickTime\qttask.exe" -atboottime
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:RunOnce, NeroHomeFirstStart
where: PE_C_CONVIDADO...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMFirstStart.exe"
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, CTFMON.EXE
where: PE_C_MAMAN ET PAPA...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:Run, QuickTime Task
where: PE_C_MAMAN ET PAPA...
command: "C:\Programas\QuickTime\qttask.exe" -atboottime
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-19...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-20...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: HK_CU:Run, IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, MyWebSearch Email Plugin
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
file: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
size: 28672
MD5: DD59256AD65F4CDCA0BCE69216AE403B

Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: D:\Spybot - Search & Destroy\TeaTimer.exe
file: D:\Spybot - Search & Destroy\TeaTimer.exe
size: 2097488
MD5: A9A5DB6AC3721BE698B996913693D73F

Located: HK_CU:Run, SweetIM
where: S-1-5-21-1177238915-1202660629-1060284298-1003...
command: C:\Programas\Macrogaming\SweetIM\SweetIM.exe
file: C:\Programas\Macrogaming\SweetIM\SweetIM.exe
size: 40960
MD5: 074F93E24502973FDA2ED859949435D5

Located: HK_CU:Run, ALUAlert
where: S-1-5-18...
command: C:\Programas\Symantec\LiveUpdate\ALUNotify.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-18...
command: C:\WINDOWS\system32\CTFMON.EXE
file: C:\WINDOWS\system32\CTFMON.EXE
size: 15360
MD5: 62B37F1F519A08AF502E6F6BB41D2DFF

Located: Démarrage (tous utilisateurs), AutoCAD Startup Accelerator.lnk
where: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque...
command: C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
file: C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
size: 10872
MD5: 9CBDBAF045D9572E3297E030820A21C1

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, fsmgmt
command: fsmgmt.dll
file: fsmgmt.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the check
0
le Douanier Messages postés 44 Statut Membre 3
 
tu doit aller dans c progame files et trouver norton et le supprimer ou regarde dans ta suppression des progammes car pour moi norton est encore la . et apres met spybot .
0
lilyne
 
norton n'y est plus et je me souvien l'avoir effacé il y a quelques mois. comment expliquer que norton.exe aparaisse sur le disque c alors que je ne le trouve pas?
0
le douanier
 
essaye de lancer une recherche de dossier!!!!
0