Procédure préliminaire de désinfection
Emi
-
anthony5151 Messages postés 10927 Statut Contributeur sécurité -
anthony5151 Messages postés 10927 Statut Contributeur sécurité -
Bonjour,
suite à la réalisation de la procédure "préliminaire de désinfection" voici mes les différents rapports obtenus:
AVG anti-spyware : rapport
j'ai perdu le rapport !!
Rapport BitDefender Online Scanner
Scan report generated at: Sat, Sep 06, 2008 - 02:50:20
Scan path: A:\;C:\;D:\;F:\;G:\;
Statistics
Time
01:53:30
Files
326859
Folders
6651
Boot Sectors
0
Archives
4973
Packed Files
15618
Results
Identified Viruses
37
Infected Files
191
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
262
Engines Info
Virus Definitions
1727480
Engine build
AVCORE v1.7 (build 8314.19) (i386) (Aug 11 2008 17:31:32)
Scan plugins
16
Archive plugins
43
Unpack plugins
7
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Emilie\Local Settings\Temp\setup1038.exe
Infected with: Trojan.Downloader.JKNS
C:\Documents and Settings\Emilie\Local Settings\Temp\setup1038.exe
Deleted
C:\Documents and Settings\Emilie\Mes documents\Ma musique\nouvelle star 2008\nouvelle star 2008 amandine.mp3
Infected with: Trojan.Downloader.WMA.Wimad.S
C:\Documents and Settings\Emilie\Mes documents\Ma musique\nouvelle star 2008\nouvelle star 2008 amandine.mp3
Deleted
C:\Easydivx\softs\ck.exe
Detected with: Application.Prockill.BL
C:\Easydivx\softs\ck.exe
Disinfection failed
C:\Easydivx\softs\ck.exe
Deleted
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Infected with: Dropped:Adware.Betterinternet.BX
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Disinfection failed
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Deleted
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)
Update failed
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Infected with: Dropped:Adware.Betterinternet.BX
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Disinfection failed
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Deleted
C:\Program Files\divx.exe=>(NSIS o)
Update failed
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Detected with: Application.Overnet.H
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Disinfection failed
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Deleted
C:\Program Files\edonkey0.53.exe=>(NSIS o)
Update failed
C:\Program Files\MSA\msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\Program Files\MSA\msa1.dat
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Detected with: Application.Pwcrack.Passview.H
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll=>(Quarantine-2)
Detected with: Adware.Betterinternet.BX
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Infected with: Trojan.Swizzor.1
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Detected with: Application.Winfixer.CF
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0002
Infected with: Trojan.Downloader.Purityscan.EH
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0002
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)
Update failed
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Softomate.BG
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)
Update failed
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Infected with: Trojan.Swizzor.1
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1=>(Quarantine-2)
Infected with: Trojan.P2P.Fontra.A
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.Wimad.A
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL=>(Quarantine-2)
Infected with: Trojan.Generic.236753
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf=>(Quarantine-2)
Infected with: Trojan.Downloader.Istbar.PY
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Detected with: Application.Winfixer.CF
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl=>(Quarantine-2)
Infected with: Trojan.FakeAV.AO
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe=>(Quarantine-2)
Infected with: MemScan:Trojan.Downloader.Apropo.H
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe=>(Quarantine-2)
Infected with: MemScan:Adware.Generic.31494
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Detected with: Application.Pwcrack.Passview.H
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe
Deleted
C:\Program Files\WildArcade\BlasterBlocks\blaster_blocks_demo.exe
Infected with: Trojan.Statblasterad.D
C:\Program Files\WildArcade\BlasterBlocks\blaster_blocks_demo.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe=>(Quarantine-2)
Infected with: Trojan.Generic.224079
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe=>(Quarantine-2)
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342380.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342380.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342406.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342406.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342478.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342478.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342512.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342512.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342514.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342514.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342695.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342695.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342697.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342697.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343154.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343154.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343216.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343216.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0002
Infected with: Rootkit.Agent.EV
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0002
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Softomate.BG
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343736.EXE=>(NSIS o)=>zlib_nsis0017
Detected with: Adware.Toolbar.Searchit.C
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343736.EXE=>(NSIS o)=>zlib_nsis0017
Deleted
C:\System Volume Information\_res
suite à la réalisation de la procédure "préliminaire de désinfection" voici mes les différents rapports obtenus:
AVG anti-spyware : rapport
j'ai perdu le rapport !!
Rapport BitDefender Online Scanner
Scan report generated at: Sat, Sep 06, 2008 - 02:50:20
Scan path: A:\;C:\;D:\;F:\;G:\;
Statistics
Time
01:53:30
Files
326859
Folders
6651
Boot Sectors
0
Archives
4973
Packed Files
15618
Results
Identified Viruses
37
Infected Files
191
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
262
Engines Info
Virus Definitions
1727480
Engine build
AVCORE v1.7 (build 8314.19) (i386) (Aug 11 2008 17:31:32)
Scan plugins
16
Archive plugins
43
Unpack plugins
7
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Emilie\Local Settings\Temp\setup1038.exe
Infected with: Trojan.Downloader.JKNS
C:\Documents and Settings\Emilie\Local Settings\Temp\setup1038.exe
Deleted
C:\Documents and Settings\Emilie\Mes documents\Ma musique\nouvelle star 2008\nouvelle star 2008 amandine.mp3
Infected with: Trojan.Downloader.WMA.Wimad.S
C:\Documents and Settings\Emilie\Mes documents\Ma musique\nouvelle star 2008\nouvelle star 2008 amandine.mp3
Deleted
C:\Easydivx\softs\ck.exe
Detected with: Application.Prockill.BL
C:\Easydivx\softs\ck.exe
Disinfection failed
C:\Easydivx\softs\ck.exe
Deleted
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Infected with: Dropped:Adware.Betterinternet.BX
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Disinfection failed
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)=>lzma_solid_nsis0016
Deleted
C:\Program Files\divx-1.0.3.exe=>(NSIS o)=>zlib_nsis0002=>(NSIS o)
Update failed
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Infected with: Dropped:Adware.Betterinternet.BX
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Disinfection failed
C:\Program Files\divx.exe=>(NSIS o)=>lzma_solid_nsis0016
Deleted
C:\Program Files\divx.exe=>(NSIS o)
Update failed
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Detected with: Application.Overnet.H
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Disinfection failed
C:\Program Files\edonkey0.53.exe=>(NSIS o)=>zlib_nsis0008
Deleted
C:\Program Files\edonkey0.53.exe=>(NSIS o)
Update failed
C:\Program Files\MSA\msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\Program Files\MSA\msa1.dat
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\0182442D.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\026A6A93.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\086C29F6.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\096F6D5E.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Detected with: Application.Pwcrack.Passview.H
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\11AD4D9E.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D15562.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\14D47F5F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll=>(Quarantine-2)
Detected with: Adware.Betterinternet.BX
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.dll
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Infected with: Trojan.Swizzor.1
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\15524B67.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\168851CB.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\17C76221.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\1E4D79BB.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\26290115.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\28CC2DB1.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2944380D.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe=>(Quarantine-2)
Detected with: Adware.FakeAntiVirus.J
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\294D3603.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\29693B5F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Detected with: Application.Winfixer.CF
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\2B533A15.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\339D2D49.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0002
Infected with: Trojan.Downloader.Purityscan.EH
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0002
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)
Update failed
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Softomate.BG
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\34E004B7.exe=>(Quarantine-2)=>(NSIS o)
Update failed
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\37BF11E2.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\387F7DE9.EXE
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Infected with: Trojan.Swizzor.1
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3CD76B4D.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1=>(Quarantine-2)
Infected with: Trojan.P2P.Fontra.A
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\3EE159A1
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Detected with: Application.Aseye.BEK
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\42624277.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\451D3B75.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4669544F.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.Wimad.A
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\486E1C1F.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL=>(Quarantine-2)
Infected with: Trojan.Generic.236753
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\4B545C2F.DLL
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\50C471D1.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Infected with: Trojan.FatObfus.Gen
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\533D54FD.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5781174B.mpg
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf=>(Quarantine-2)
Infected with: Trojan.Downloader.Istbar.PY
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5B5F9E.inf
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Detected with: Application.Winfixer.CF
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5B5F099B.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\619168B7.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl=>(Quarantine-2)
Infected with: Trojan.FakeAV.AO
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\63AF2656.cpl
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe=>(Quarantine-2)
Infected with: Backdoor.Genlot.KK
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6BDC62D0.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe=>(Quarantine-2)
Infected with: MemScan:Trojan.Downloader.Apropo.H
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6D7563F5.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe=>(Quarantine-2)
Infected with: MemScan:Adware.Generic.31494
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\6DC816BA.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3=>(Quarantine-2)
Infected with: Trojan.Downloader.WMA.Wimad.N
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\72F8576A.mp3
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Detected with: Application.Pwcrack.Passview.H
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\73E004C7.exe
Deleted
C:\Program Files\WildArcade\BlasterBlocks\blaster_blocks_demo.exe
Infected with: Trojan.Statblasterad.D
C:\Program Files\WildArcade\BlasterBlocks\blaster_blocks_demo.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe=>(Quarantine-2)
Infected with: Trojan.Generic.224079
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe=>(Quarantine-2)
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1294\A0340455.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342325.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342331.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342332.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342380.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342380.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342406.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342406.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342461.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342462.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342468.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342469.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342477.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342478.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342478.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342480.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342509.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342510.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342512.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342512.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342514.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342514.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342515.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342523.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342524.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342652.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342658.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342659.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342667.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342684.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342685.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342691.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342695.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342695.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342697.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342697.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342698.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343143.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343154.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343154.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343161.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>5.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)=>7.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343178.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343190.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343191.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.exe
Detected with: Adware.FakeAntiVirus.J
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>MSA.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa0.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa0.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa1.dat
Infected with: Trojan.FakeAlert.ACZ
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)=>msa1.dat
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343199.exe=>(RAR Sfx o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343200.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Infected with: Trojan.Downloader.Exchanger.Gen.2
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Disinfection failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343211.exe
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343216.cpl
Infected with: Trojan.FakeAV.AO
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343216.cpl
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0002
Infected with: Rootkit.Agent.EV
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0002
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0004
Detected with: Adware.Softomate.BG
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)=>lzma_solid_nsis0004
Deleted
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343736.EXE=>(NSIS o)=>zlib_nsis0017
Detected with: Adware.Toolbar.Searchit.C
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343736.EXE=>(NSIS o)=>zlib_nsis0017
Deleted
C:\System Volume Information\_res
A voir également:
- Procédure préliminaire de désinfection
- Le point d'entree de procedure est introuvable kernel32 dll ✓ - Forum Windows
- Le point d'entrée de procédure est introuvable dans la bibliothèque de liens dynamiques ✓ - Forum Logiciels
- Le point d'entrée de procédure iswow64process2 est introuvable - Forum Windows
- Le point d'entrée de procédure discard virtual memory est introuvable ✓ - Forum Windows
- Le point d'entrée de procédure copyfile2 est introuvable ✓ - Forum Logiciels
14 réponses
J'ai relu le message 3 fois, mais je me sens un peu bête... Je ne vois pas du coup ce que tu cherches à savoir... :S
Tu as fait un scan, ok... Et...?
J'ai dû louper une ligne...
Tu as fait un scan, ok... Et...?
J'ai dû louper une ligne...
j'ai suivi la procédure indiquée, sur le site mais mes problèmes subsistent.
Il m'était conseillé d'envoyer les rapports des analyses afin qu'un expert puisse éventuellement identifier le problème.
J'ai en permanence un fenêtre qui s'ouvrent : sans aucun doute un virus ou autre: il m'indique Windows Security Alert et me demande de télécharger un logiciel .
Il m'était conseillé d'envoyer les rapports des analyses afin qu'un expert puisse éventuellement identifier le problème.
J'ai en permanence un fenêtre qui s'ouvrent : sans aucun doute un virus ou autre: il m'indique Windows Security Alert et me demande de télécharger un logiciel .
Bonjour,
Le rapport de BitDefender est tellement long qu'il manque la fin (peu importe)
Il faudrait par contre le rapport hijackthis. Si tu ne l'as pas encore fait, suis cette procédure :
Télécharge hijackthis sur ton bureau : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
Installe le, puis fais ceci avant de le lancer :
Va dans le menu démarrer --> Poste de travail --> disque local C --> Program Files --> Trend Micro --> Hijackthis --> cherche hijackthis.exe et fais un clic droit dessus --> renomme le en Jack.exe
Ensuite lance le et clique sur "Do a system scan and save a logfile".
Fais un copier-coller du rapport entier sur le forum
Le rapport de BitDefender est tellement long qu'il manque la fin (peu importe)
Il faudrait par contre le rapport hijackthis. Si tu ne l'as pas encore fait, suis cette procédure :
Télécharge hijackthis sur ton bureau : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
Installe le, puis fais ceci avant de le lancer :
Va dans le menu démarrer --> Poste de travail --> disque local C --> Program Files --> Trend Micro --> Hijackthis --> cherche hijackthis.exe et fais un clic droit dessus --> renomme le en Jack.exe
Ensuite lance le et clique sur "Do a system scan and save a logfile".
Fais un copier-coller du rapport entier sur le forum
Bonjour
ci dessous rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:12:16, on 06/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/fHZ9tcxV2kmZ0hAR0p3/ikCFwxPl5FOTbfjeNlHMhkVIjOlC1QnWWJSw1TMwNIvb.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKLM\..\Run: [Microsoft Update] muamgrd.exe
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [SfKg6w] C:\WINDOWS\fdamnf.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://www.m6video.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.netprint.com/view/uploader/ImageUploader3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C80B7FF6-CE60-4079-935E-520C045C30A6} - http://www.mailskinner.com/binaries/msaxsetup.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
ci dessous rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:12:16, on 06/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/fHZ9tcxV2kmZ0hAR0p3/ikCFwxPl5FOTbfjeNlHMhkVIjOlC1QnWWJSw1TMwNIvb.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKLM\..\Run: [Microsoft Update] muamgrd.exe
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [SfKg6w] C:\WINDOWS\fdamnf.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://www.m6video.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.netprint.com/view/uploader/ImageUploader3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C80B7FF6-CE60-4079-935E-520C045C30A6} - http://www.mailskinner.com/binaries/msaxsetup.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
Ton ordinateur est très mal protégé (Windows et logiciels pas à jour, logiciels de sécurité inefficaces...), et donc très infecté...
1) Commence par faire ce scan
Télécharge et installe Malwarebyte's Anti-Malware : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
- A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
- Lance Malwarebyte's Anti-Malware, laisse les Mises à jour se télécharger et referme le programme
Redémarre en "Mode sans échec" : redémarre ton ordinateur et tapote sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows, et sélectionne "Mode sans échec".
Choisis ta session habituelle
Lance Malwarebyte's Anti-Malware
- Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
- Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
- A la fin du scan, clique sur Afficher les résultats puis sur Enregistrer le rapport
- Suppression des éléments détectés --> clique sur Supprimer la sélection
- S'il t'es demandé de redémarrer, clique sur Yes
Poste le rapport de scan après la suppression ici
2) Poste un nouveau rapport hijackthis stp
1) Commence par faire ce scan
Télécharge et installe Malwarebyte's Anti-Malware : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
- A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
- Lance Malwarebyte's Anti-Malware, laisse les Mises à jour se télécharger et referme le programme
Redémarre en "Mode sans échec" : redémarre ton ordinateur et tapote sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows, et sélectionne "Mode sans échec".
Choisis ta session habituelle
Lance Malwarebyte's Anti-Malware
- Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
- Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
- A la fin du scan, clique sur Afficher les résultats puis sur Enregistrer le rapport
- Suppression des éléments détectés --> clique sur Supprimer la sélection
- S'il t'es demandé de redémarrer, clique sur Yes
Poste le rapport de scan après la suppression ici
2) Poste un nouveau rapport hijackthis stp
ci dessous les rapports demandés :
Rapport du scan malwarebyte :
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1120
Windows 5.1.2600
06/09/2008 21:40:44
mbam-log-2008-09-06 (21-40-44).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 131589
Temps écoulé: 2 hour(s), 49 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 26
Valeur(s) du Registre infectée(s): 16
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 94
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{3947ac1d-db09-4353-bbcc-55b97f5035ef} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a58f3d09-4543-4396-8be7-105f14dd6ed5} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{469c7080-8ec8-43a6-ad97-45848113743c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c80b7ff6-ce60-4079-935e-520c045c30a6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0e594d22-ace6-43a2-bcda-bb7c65d3fe8c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{511f9316-771b-4953-a268-1c36da667fe9} (Dialer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0594af7e-573b-40df-8165-e47ab2eaefe8} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{469c7080-8ec8-43a6-ad97-45848113743c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{c80b7ff6-ce60-4079-935e-520c045c30a6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\navipromo.egnaviscoring (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\navipromo.egnaviscoring.1 (Adware.EGDAccess) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a5.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a8.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a5.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a8.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Update (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SfKg6w (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update Machine (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update Machine (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Ipwindows (Trojan.Rond) -> Quarantined and deleted successfully.
C:\WINDOWS\msskinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Program Files\Avast_install_setupfre.exe (Backdoor.Small) -> Quarantined and deleted successfully.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342326.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342327.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342329.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342330.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342374.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342470.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342471.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342473.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342481.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342482.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342484.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342517.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342518.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342520.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342525.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342526.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342528.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342582.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342653.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342654.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342656.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342657.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342663.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342665.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342666.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342668.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342670.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342677.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342693.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342755.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343118.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe (Adware.SoftMate) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343738.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\MSA\MSA.ooo (Rogue.MSAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\A.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\b.zip (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\B.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\c.zip (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\fdamnf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Program Files\Setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\wr.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ClickToFindandFixErrors_RON_Intl.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\EGAUTH.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\nethv32.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mseggrpid.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvknjzbyq_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvknjzbyq_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
Rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55:44, on 06/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/fHZ9tcxV2kmZ0hAR0p3/ikCFwxPl5FOTbfjeNlHMhkVIjOlC1QnWWJSw1TMwNIvb.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe,
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CJava Object - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\System32\msjava32.dll (file missing)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - C:\WINDOWS\System32\fgremmk.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - C:\WINDOWS\System32\jqn.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [rvknjzbyq] c:\windows\system32\rvknjzbyq.exe rvknjzbyq
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\Emilie\LOCALS~1\Temp\setup1038.exe
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} -
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://www.m6video.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.netprint.com/view/uploader/ImageUploader3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C80B7FF6-CE60-4079-935E-520C045C30A6} -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
Rapport du scan malwarebyte :
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1120
Windows 5.1.2600
06/09/2008 21:40:44
mbam-log-2008-09-06 (21-40-44).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 131589
Temps écoulé: 2 hour(s), 49 minute(s), 49 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 26
Valeur(s) du Registre infectée(s): 16
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 94
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{3947ac1d-db09-4353-bbcc-55b97f5035ef} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a58f3d09-4543-4396-8be7-105f14dd6ed5} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{469c7080-8ec8-43a6-ad97-45848113743c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c80b7ff6-ce60-4079-935e-520c045c30a6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0e594d22-ace6-43a2-bcda-bb7c65d3fe8c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{511f9316-771b-4953-a268-1c36da667fe9} (Dialer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0594af7e-573b-40df-8165-e47ab2eaefe8} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{469c7080-8ec8-43a6-ad97-45848113743c} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{c80b7ff6-ce60-4079-935e-520c045c30a6} (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\navipromo.egnaviscoring (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\navipromo.egnaviscoring.1 (Adware.EGDAccess) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a5.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a8.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a5.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\vie1a8.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Update (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SfKg6w (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update Machine (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update Machine (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Ipwindows (Trojan.Rond) -> Quarantined and deleted successfully.
C:\WINDOWS\msskinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Program Files\Avast_install_setupfre.exe (Backdoor.Small) -> Quarantined and deleted successfully.
C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342326.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342327.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342329.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342330.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1332\A0342374.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342470.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342471.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342473.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342481.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342482.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1336\A0342484.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342517.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342518.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342520.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342525.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342526.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342528.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342529.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342582.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342653.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342654.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342656.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342657.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342663.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342665.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342666.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342668.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1338\A0342670.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342677.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342693.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0342755.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1339\A0343118.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343733.exe (Adware.SoftMate) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{95253151-A24D-4501-8F72-36F80B31268A}\RP1340\A0343738.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\MSA\MSA.ooo (Rogue.MSAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\A.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\b.zip (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\B.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\c.zip (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\fdamnf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Program Files\Setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\wr.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ClickToFindandFixErrors_RON_Intl.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\EGAUTH.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\nethv32.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mseggrpid.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvknjzbyq_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvknjzbyq_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
Rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55:44, on 06/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/fHZ9tcxV2kmZ0hAR0p3/ikCFwxPl5FOTbfjeNlHMhkVIjOlC1QnWWJSw1TMwNIvb.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe,
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CJava Object - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\System32\msjava32.dll (file missing)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - C:\WINDOWS\System32\fgremmk.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - C:\WINDOWS\System32\jqn.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [rvknjzbyq] c:\windows\system32\rvknjzbyq.exe rvknjzbyq
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\Emilie\LOCALS~1\Temp\setup1038.exe
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: Interface Chat Voila - http://chat10.x-echo.com/version6/Applet/vchatsign.cab
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version6/Applet/wchatsign.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} -
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://www.m6video.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.netprint.com/view/uploader/ImageUploader3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C80B7FF6-CE60-4079-935E-520C045C30A6} -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildAppNonUS.cab
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
J'espère que tu as de la patience, parce qu'il reste beaucoup de travail pour venir à bout des infections de ton ordinateur...
1) Pour rendre le rapport Hijackthis un peu plus lisible, merci de refaire un scan avec hijackthis, de cocher les lignes suivantes et de cliquer sur "Fix Checked" :
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: CJava Object - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\System32\msjava32.dll (file missing)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - C:\WINDOWS\System32\fgremmk.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - C:\WINDOWS\System32\jqn.dll (file missing)
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
Coche également toutes les lignes commençant par 016
2) Ton ordinateur est infecté (entre autre !) par MagicControl/navipromo, qui s'installe via des programmes dits "gratuits", dont ceux-ci :
* go-astro
* GoRecord
* HotTVPlayer / HotTVPlayer & Paris Hilton
* Live-Player
* MailSkinner
* Messenger Skinner
* Instant Access
* InternetGameBox
* Officiale Emule (Version d'Emule modifiée)
* Sudoplanet
* Webmediaplayer
Pour désinfecter, merci de suivre exactement cette procédure :
# Désactive le TeaTimer de Spybot (tu le réactiveras quand nous aurons terminé) :
Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer
# Télécharge maintenant Navilog1 depuis-ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, lance Navilog depuis le raccourci présent sur le bureau
Au menu principal, Fais le choix 1
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche le bloc note va s'ouvrir.
Copie-colle l'intégralité du rapport ici.
1) Pour rendre le rapport Hijackthis un peu plus lisible, merci de refaire un scan avec hijackthis, de cocher les lignes suivantes et de cliquer sur "Fix Checked" :
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zsflrwxpwughd.com/
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: CJava Object - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\System32\msjava32.dll (file missing)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - C:\WINDOWS\System32\fgremmk.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - C:\WINDOWS\System32\jqn.dll (file missing)
O3 - Toolbar: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
Coche également toutes les lignes commençant par 016
2) Ton ordinateur est infecté (entre autre !) par MagicControl/navipromo, qui s'installe via des programmes dits "gratuits", dont ceux-ci :
* go-astro
* GoRecord
* HotTVPlayer / HotTVPlayer & Paris Hilton
* Live-Player
* MailSkinner
* Messenger Skinner
* Instant Access
* InternetGameBox
* Officiale Emule (Version d'Emule modifiée)
* Sudoplanet
* Webmediaplayer
Pour désinfecter, merci de suivre exactement cette procédure :
# Désactive le TeaTimer de Spybot (tu le réactiveras quand nous aurons terminé) :
Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer
# Télécharge maintenant Navilog1 depuis-ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, lance Navilog depuis le raccourci présent sur le bureau
Au menu principal, Fais le choix 1
Laisse toi guider et patiente.
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche le bloc note va s'ouvrir.
Copie-colle l'intégralité du rapport ici.
Bonjour
ci dessous le nouveau rapport hijackthis après "fix checked"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:35, on 07/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\qlqpijyl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [rvknjzbyq] c:\windows\system32\rvknjzbyq.exe rvknjzbyq
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\Emilie\LOCALS~1\Temp\setup1038.exe
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
ci dessous le nouveau rapport hijackthis après "fix checked"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:35, on 07/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe
C:\WINDOWS\system32\qlqpijyl.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pcqrb.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bxxulrl.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [rvknjzbyq] c:\windows\system32\rvknjzbyq.exe rvknjzbyq
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Microsoft Update Machine] windowsu.exe
O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\Emilie\LOCALS~1\Temp\setup1038.exe
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKLM\..\Policies\Explorer\Run: [N5jsHjLGGT] C:\Documents and Settings\All Users\Application Data\zehobyjc\balivqju.exe
O4 - HKCU\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update] muamgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{CC9BD43A-06C5-1036-1203-020801030021}] "C:\Program Files\Fichiers communs\{CC9BD43A-06C5-1036-1203-020801030021}\Update.exe" mc-110-12-0000137 (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
ci dessous rapport de Navilog
Search Navipromo version 3.6.5 commencé le 07/09/2008 à 11:59:08,18
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Emilie"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
HKEY_CURRENT_USER\Software\mc trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
rvknjzbyq.dat trouvé !
* Dans "C:\Documents and Settings\Emilie\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 07/09/2008 à 12:20:30,78 ***
Search Navipromo version 3.6.5 commencé le 07/09/2008 à 11:59:08,18
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Emilie"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Emilie\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
HKEY_CURRENT_USER\Software\mc trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
rvknjzbyq.dat trouvé !
* Dans "C:\Documents and Settings\Emilie\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 07/09/2008 à 12:20:30,78 ***
Relance Navilog à l'aide du raccourci navilog1 présent sur le bureau et laisse-toi guider.
Au menu principal, choisis 2 et valide.
Le fix va t'informer qu'il va alors redémarrer ton PC
Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuie sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.
Au menu principal, choisis 2 et valide.
Le fix va t'informer qu'il va alors redémarrer ton PC
Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuie sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.
ok ci dessous rapport demandé
Clean Navipromo version 3.6.5 commencé le 07/09/2008 à 15:12:26,21
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Emilie"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Système de fichiers : NTFS
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\menudm~1\progra~1" ***
*** Suppression fichiers ***
C:\WINDOWS\pack.epk supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Emilie\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
rvknjzbyq.dat trouvé !
Copie rvknjzbyq.dat réalisée avec succès !
rvknjzbyq.dat supprimé !
* Dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltdt absent !
*** Nettoyage terminé le 07/09/2008 à 15:18:25,20 ***
Clean Navipromo version 3.6.5 commencé le 07/09/2008 à 15:12:26,21
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Emilie"
Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Système de fichiers : NTFS
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Emilie\menudm~1\progra~1" ***
*** Suppression fichiers ***
C:\WINDOWS\pack.epk supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Emilie\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
rvknjzbyq.dat trouvé !
Copie rvknjzbyq.dat réalisée avec succès !
rvknjzbyq.dat supprimé !
* Dans "C:\Documents and Settings\Emilie\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltdt absent !
*** Nettoyage terminé le 07/09/2008 à 15:18:25,20 ***
Bien, on passe à la suite :
Télécharge MSNFix.zip (de !aur3n7) sur ton bureau : http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le (clic droit >> Extraire ici) et double clique sur le fichier MSNFix.bat.
- Exécute l'option R.
- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
--> Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt
Tutorial en image :
https://www.malekal.com/supprimer-virus-desinfecter-pc/
Télécharge MSNFix.zip (de !aur3n7) sur ton bureau : http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le (clic droit >> Extraire ici) et double clique sur le fichier MSNFix.bat.
- Exécute l'option R.
- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
--> Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt
Tutorial en image :
https://www.malekal.com/supprimer-virus-desinfecter-pc/
ok rapport MSNfix
MSNFix 1.745
C:\Documents and Settings\Emilie\Bureau\MSNFix
Fix exécuté le 07/09/2008 - 15:52:40,79 By Emilie
mode normal
************************ Recherche les fichiers présents
... C:\WINDOWS\system32\mdm.exe
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Suppression des fichiers
.. OK ... C:\DOCUME~1\Emilie\LOCALS~1\Temp\winlogon.exe
.. OK ... C:\DOCUME~1\Emilie\LOCALS~1\Temp\services.exe
.. OK ... C:\WINDOWS\system32\cftmon.exe
.. OK ... C:\WINDOWS\system32\mdm.exe
************************ Nettoyage du registre
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\WINDOWS\System32\drivers\etc\hosts-20080907160043
-- original size 257.88 Kb / 9165 lines
-- Start cleaning Hosts file ....
/!\... antivirus.com ..... Found and removed
/!\... avast.com ..... Found and removed
/!\... ca.com ..... Found and removed
/!\... mcafee.com ..... Found and removed
/!\... spybot.info ..... Found and removed
-- final size 256.31 Kb / 9123 lines
-- entry Found : 5 / Entry check : 310
End .............................. 37.44 Secondes
Les fichiers encore présents seront supprimés au prochain redémarrage
Aucun Fichier trouvé
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\WINDOWS\System32\drivers\etc\hosts-20080907160545
-- original size 256.31 Kb / 9123 lines
-- Start cleaning Hosts file ....
-- final size 256.31 Kb / 9123 lines
-- entry Found : 0 / Entry check : 310
End .............................. 47.43 Secondes
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 07092008_16063456.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\WINDOWS\system32\userinit.exe,
Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
MSNFix 1.745
C:\Documents and Settings\Emilie\Bureau\MSNFix
Fix exécuté le 07/09/2008 - 15:52:40,79 By Emilie
mode normal
************************ Recherche les fichiers présents
... C:\WINDOWS\system32\mdm.exe
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Suppression des fichiers
.. OK ... C:\DOCUME~1\Emilie\LOCALS~1\Temp\winlogon.exe
.. OK ... C:\DOCUME~1\Emilie\LOCALS~1\Temp\services.exe
.. OK ... C:\WINDOWS\system32\cftmon.exe
.. OK ... C:\WINDOWS\system32\mdm.exe
************************ Nettoyage du registre
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\WINDOWS\System32\drivers\etc\hosts-20080907160043
-- original size 257.88 Kb / 9165 lines
-- Start cleaning Hosts file ....
/!\... antivirus.com ..... Found and removed
/!\... avast.com ..... Found and removed
/!\... ca.com ..... Found and removed
/!\... mcafee.com ..... Found and removed
/!\... spybot.info ..... Found and removed
-- final size 256.31 Kb / 9123 lines
-- entry Found : 5 / Entry check : 310
End .............................. 37.44 Secondes
Les fichiers encore présents seront supprimés au prochain redémarrage
Aucun Fichier trouvé
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\WINDOWS\System32\drivers\etc\hosts-20080907160545
-- original size 256.31 Kb / 9123 lines
-- Start cleaning Hosts file ....
-- final size 256.31 Kb / 9123 lines
-- entry Found : 0 / Entry check : 310
End .............................. 47.43 Secondes
************************ Fichiers suspects
Aucun Fichier trouvé
Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 07092008_16063456.zip
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\WINDOWS\system32\userinit.exe,
Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.ionos.fr/
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
Très bien ;) On passe à SDFix maintenant
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
• Puis, ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau rapport Hijackthis !
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
• Puis, ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau rapport Hijackthis !
ci dessous rapport SDFix
[b]SDFix: Version 1.222 [/b]
Run by Emilie on 07/09/2008 at 20:23
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Emilie\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\FTPUPD.EXE - Deleted
C:\WINDOWS\SYSTEM32\TASKKILL.EXE - Deleted
C:\WINDOWS\system32\n.bat - Deleted
C:\WINDOWS\system32\TFTP1164 - Deleted
C:\WINDOWS\system32\TFTP1300 - Deleted
C:\WINDOWS\system32\TFTP1344 - Deleted
C:\WINDOWS\system32\TFTP1684 - Deleted
C:\WINDOWS\system32\TFTP2064 - Deleted
C:\WINDOWS\system32\TFTP2184 - Deleted
C:\WINDOWS\system32\TFTP2200 - Deleted
C:\WINDOWS\system32\TFTP2320 - Deleted
C:\WINDOWS\system32\TFTP2680 - Deleted
C:\WINDOWS\system32\TFTP2704 - Deleted
C:\WINDOWS\system32\TFTP3088 - Deleted
C:\WINDOWS\system32\TFTP3160 - Deleted
C:\WINDOWS\system32\TFTP324 - Deleted
C:\WINDOWS\system32\TFTP3392 - Deleted
C:\WINDOWS\system32\TFTP3408 - Deleted
C:\WINDOWS\system32\TFTP3740 - Deleted
C:\WINDOWS\system32\TFTP3780 - Deleted
C:\WINDOWS\system32\TFTP3840 - Deleted
C:\WINDOWS\system32\TFTP3976 - Deleted
C:\WINDOWS\system32\TFTP4000 - Deleted
C:\Program Files\Track_03.exe - Deleted
C:\Program Files\Video.exe - Deleted
x.dat and z.dat data copied to \SDFix\Data.txt
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 20:53:17
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\Emilie\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Sun 29 Aug 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 18 Aug 2005 19,456 ...H. --- "C:\Documents and Settings\Emilie\Application Data\Microsoft\Word\~WRL1711.tmp"
Sun 29 Aug 2004 4,348 ...H. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Fri 7 Jan 2005 20 A..H. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 28 Aug 2004 312 A.SH. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Thu 12 Jun 2008 0 A..H. --- "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\BIT23.tmp"
Wed 11 Jun 2008 0 A..H. --- "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\BITADF.tmp"
[b]Finished![/b]
Ci dessous le rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:26, on 07/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\Jack.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {43F7497C-7687-4DEA-A057-F21BD81BC896} - (no file)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
O16 - DPF: Interface Chat Voila -
O16 - DPF: Interface Chat Wanadoo -
O16 - DPF: Yahoo! Chat -
O16 - DPF: {00000000-0000-0000-0000-000020030000} -
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} -
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} -
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} -
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} -
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
[b]SDFix: Version 1.222 [/b]
Run by Emilie on 07/09/2008 at 20:23
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Emilie\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\FTPUPD.EXE - Deleted
C:\WINDOWS\SYSTEM32\TASKKILL.EXE - Deleted
C:\WINDOWS\system32\n.bat - Deleted
C:\WINDOWS\system32\TFTP1164 - Deleted
C:\WINDOWS\system32\TFTP1300 - Deleted
C:\WINDOWS\system32\TFTP1344 - Deleted
C:\WINDOWS\system32\TFTP1684 - Deleted
C:\WINDOWS\system32\TFTP2064 - Deleted
C:\WINDOWS\system32\TFTP2184 - Deleted
C:\WINDOWS\system32\TFTP2200 - Deleted
C:\WINDOWS\system32\TFTP2320 - Deleted
C:\WINDOWS\system32\TFTP2680 - Deleted
C:\WINDOWS\system32\TFTP2704 - Deleted
C:\WINDOWS\system32\TFTP3088 - Deleted
C:\WINDOWS\system32\TFTP3160 - Deleted
C:\WINDOWS\system32\TFTP324 - Deleted
C:\WINDOWS\system32\TFTP3392 - Deleted
C:\WINDOWS\system32\TFTP3408 - Deleted
C:\WINDOWS\system32\TFTP3740 - Deleted
C:\WINDOWS\system32\TFTP3780 - Deleted
C:\WINDOWS\system32\TFTP3840 - Deleted
C:\WINDOWS\system32\TFTP3976 - Deleted
C:\WINDOWS\system32\TFTP4000 - Deleted
C:\Program Files\Track_03.exe - Deleted
C:\Program Files\Video.exe - Deleted
x.dat and z.dat data copied to \SDFix\Data.txt
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 20:53:17
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\Emilie\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Sun 29 Aug 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 18 Aug 2005 19,456 ...H. --- "C:\Documents and Settings\Emilie\Application Data\Microsoft\Word\~WRL1711.tmp"
Sun 29 Aug 2004 4,348 ...H. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Fri 7 Jan 2005 20 A..H. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 28 Aug 2004 312 A.SH. --- "C:\Documents and Settings\Emilie\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Thu 12 Jun 2008 0 A..H. --- "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\BIT23.tmp"
Wed 11 Jun 2008 0 A..H. --- "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\BITADF.tmp"
[b]Finished![/b]
Ci dessous le rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:26, on 07/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\M6Video\M6video.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\qlqpijyl.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Aide mémoire\TrayIcon.exe
C:\Program Files\PROMT98\INTEGRAL\pinmenu.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\Jack.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = https://www.tiscali.it/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - _{34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {43F7497C-7687-4DEA-A057-F21BD81BC896} - (no file)
O2 - BHO: (no name) - {4FA6422C-E135-2FB6-8659-635579A6266C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {B1043A6F-D8D8-8E5F-DB07-8CADAEB872E0} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fr-ch\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Ins3DT] D:\INSTALL4\INS3DT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr-ch\msnappau.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [m6] C:\Program Files\M6Video\M6video.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [omwdal] C:\WINDOWS\System32\eaiwig.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Tyzvo] C:\Program Files\Vqwzj\Vlssmu.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\MWSBAR.DLL,S
O4 - HKLM\..\RunServices: [Microsoft Sysgrade] winbt32.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Microsoft Sysgrade] winbt32.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [MsgWebSys] C:\WINDOWS\system32\qlqpijyl.exe
O4 - HKCU\..\Run: [dbprocact] C:\WINDOWS\system32\tkfevqpk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [\VIE1A2.exe] C:\Windows\System32\VIE1A2.exe
O4 - HKCU\..\Run: [\VIE1A3.exe] C:\Windows\System32\VIE1A3.exe
O4 - HKCU\..\Run: [\VIE1A4.exe] C:\Windows\System32\VIE1A4.exe
O4 - HKCU\..\Run: [\VIE1A5.exe] C:\Windows\System32\VIE1A5.exe
O4 - HKCU\..\Run: [\VIE1A8.exe] C:\Windows\System32\VIE1A8.exe
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Sysgrade] winbt32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI VIDEO REGKEY] ati2vid.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Service Pack2] svchhost.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Process Session Manager] pidserv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Update Machine] expl0rer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Windows Driver Services] msdrvs32.exe (User 'Default user')
O4 - Startup: Aide mémoire.lnk = ?
O4 - Startup: Intégrateur PROjectMT 98.lnk = C:\Program Files\PROMT98\INTEGRAL\PINSTART.EXE
O4 - Global Startup: dllhost.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - ?p=ZSzeb02969FR_ZN
O8 - Extra context menu item: &Search the Web - C:\WINDOWS\Web\Ers_src.htm
O8 - Extra context menu item: Personnaliser - C:\Program Files\PROMT98\promtie4\options.htm
O8 - Extra context menu item: Rechercher sur Internet - C:\Program Files\PROMT98\promtie4\search.htm
O8 - Extra context menu item: Traduire - C:\Program Files\PROMT98\promtie4\translat.htm
O8 - Extra context menu item: Traduire dans WebView - C:\Program Files\PROMT98\promtie4\webview.htm
O8 - Extra context menu item: Traduire la page - C:\Program Files\PROMT98\promtie4\page.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - C:\Program Files\PROMT98\promtie4\promtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - C:\Program Files\PROMT98\promtie4\options.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
O16 - DPF: Interface Chat Voila -
O16 - DPF: Interface Chat Wanadoo -
O16 - DPF: Yahoo! Chat -
O16 - DPF: {00000000-0000-0000-0000-000020030000} -
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} -
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} -
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} -
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} -
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} -
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} -
O18 - Protocol: bw+0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {30EAAFC1-867F-49BD-A4E5-A4F1BDA6ED96} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\DJSNETCN.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
Excellent, on avance :)
J'espère que tu es patient, il reste quand même pas mal de choses à faire...
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
J'espère que tu es patient, il reste quand même pas mal de choses à faire...
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
Bonjour
désolé mais je ne pourrai être présent que le soir, de la patiente j'en aurai assez
j'espère que toi aussi pour m'aider à venir à bout de mes problèmes, en tout cas je te remercie
Ci dessous rapport Toolbar
-----------\\ ToolBar S&D 1.1.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 )
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2100+ )
BIOS : Version 07.00T
USER : Emilie ( Administrator )
BOOT : Normal boot
"C:\ToolBar SD" ( MAJ : 07-09-2008|12:20 )
Option : [1] ( 08/09/2008|20:25 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\System32\\blank.htm"
"Start Page"="https://portail.free.fr/"
"Start Page_bak"="https://www.tiscali.it/"
"Search Page_bak"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5"
"First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.ustart.org"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\I am\De la planŠte Mars\IAM (1991) - ...De La Plan‚te Mars - 06 - Crack.mp3
C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\kerry james\Le Monde a Crack‚.mp3
C:\DOCUME~1\Emilie\Shared\_\Astro Hunter 3D Deluxe v2.1 (c) SB-Software Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Crack.House.1989.WS.DVDRip.XviD-KVS.zip
C:\DOCUME~1\Emilie\Shared\_\Gem Ball Ancient Legends v1.09 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Mahjong Escape Ancient Japan v1.0.0.1 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MahJong Suite 2007 v4.0 KeyGen Only .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Canasta v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Cribbage v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Euchre And Ecarte v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Gin Rummy v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Pinochle And Bezique v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Piquet v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Rummy 500 v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Missile Commander XP v1.2 (c) SB-Software Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\PuzzleJoy v1.0.6 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Sam And Max Season 1 Culture Shock V1.0 CRACKFIX.zip
C:\DOCUME~1\Emilie\Shared\_\Sudoku 9981 v4.01 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\The Treasures of Montezuma v1.06 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Zombie Smashers X2 v1.0 Incl Keygen .zip
C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack.zip
C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack1.zip
1 - "C:\ToolBar SD\TB_1.txt" - 08/09/2008|20:27 - Option : [1]
-----------\\ Fin du rapport a 20:27:35,09
désolé mais je ne pourrai être présent que le soir, de la patiente j'en aurai assez
j'espère que toi aussi pour m'aider à venir à bout de mes problèmes, en tout cas je te remercie
Ci dessous rapport Toolbar
-----------\\ ToolBar S&D 1.1.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 )
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2100+ )
BIOS : Version 07.00T
USER : Emilie ( Administrator )
BOOT : Normal boot
"C:\ToolBar SD" ( MAJ : 07-09-2008|12:20 )
Option : [1] ( 08/09/2008|20:25 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\System32\\blank.htm"
"Start Page"="https://portail.free.fr/"
"Start Page_bak"="https://www.tiscali.it/"
"Search Page_bak"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5"
"First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.ustart.org"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\I am\De la planŠte Mars\IAM (1991) - ...De La Plan‚te Mars - 06 - Crack.mp3
C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\kerry james\Le Monde a Crack‚.mp3
C:\DOCUME~1\Emilie\Shared\_\Astro Hunter 3D Deluxe v2.1 (c) SB-Software Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Crack.House.1989.WS.DVDRip.XviD-KVS.zip
C:\DOCUME~1\Emilie\Shared\_\Gem Ball Ancient Legends v1.09 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Mahjong Escape Ancient Japan v1.0.0.1 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MahJong Suite 2007 v4.0 KeyGen Only .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Canasta v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Cribbage v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Euchre And Ecarte v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Gin Rummy v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Pinochle And Bezique v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Piquet v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Rummy 500 v2007.70117 (c) MeggieSoft Games Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Missile Commander XP v1.2 (c) SB-Software Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\PuzzleJoy v1.0.6 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Sam And Max Season 1 Culture Shock V1.0 CRACKFIX.zip
C:\DOCUME~1\Emilie\Shared\_\Sudoku 9981 v4.01 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\The Treasures of Montezuma v1.06 Incl Keygen .zip
C:\DOCUME~1\Emilie\Shared\_\Zombie Smashers X2 v1.0 Incl Keygen .zip
C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack.zip
C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack1.zip
1 - "C:\ToolBar SD\TB_1.txt" - 08/09/2008|20:27 - Option : [1]
-----------\\ Fin du rapport a 20:27:35,09
Je comprends mieux pourquoi ton ordinateur est autant infecté ! Les cracks et keygens sont à bannir, la plupart d'entre eux sont infectés : https://forum.malekal.com/viewtopic.php?f=33&t=893
Désinstalle tes logiciels crackés et supprime tous tes keygens, sinon ça ne sert à rien de continuer, les infections présentes sur ton ordinateur reviendront tout le temps ! Et ton ordinateur restera ouvert à tous les pirates...
Désinstalle tes logiciels crackés et supprime tous tes keygens, sinon ça ne sert à rien de continuer, les infections présentes sur ton ordinateur reviendront tout le temps ! Et ton ordinateur restera ouvert à tous les pirates...
A la fin de la recherche de toolbar S&D, il y a une liste dans la partie "Cracks & Keygens". Mis à part les deux mp3 qui ne sont peut-être que de la musique (à voir), le reste est à supprimer.
Tu es sûr qu'aucun utilisateur de l'ordinateur n'a téléchargé ces fichiers ? Si c'est le cas, c'est peut-être une des infections qui les a téléchargé et qui les partage sur un réseau P2P (Emule, LimeWire, BitTorrent...) à ton insu, pour diffuser l'infection à d'autres...
Tu es sûr qu'aucun utilisateur de l'ordinateur n'a téléchargé ces fichiers ? Si c'est le cas, c'est peut-être une des infections qui les a téléchargé et qui les partage sur un réseau P2P (Emule, LimeWire, BitTorrent...) à ton insu, pour diffuser l'infection à d'autres...
crack : http://fr.wikipedia.org/wiki/Crack_(informatique)
keygen : https://fr.wikipedia.org/wiki/Keygen
Au passage, j'ai une question : ta version de Windows XP n'est pas officielle je suppose ?
Toolbar S&D ne supprime pas les cracks (ce n'est pas sa fonction), il les signale seulement. Pour les supprimer, il faut le faire manuellement, mais tu peux utiliser ce programme pour le faire si tu veux :
Télécharge OTMoveIt (de Old_Timer) sur ton bureau...
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
# Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
Copie le texte ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.
Clique sur MoveIt! pour lancer la suppression.
Lorsque un résultat apparaît dans le cadre Results, clique sur Exit et redémarre ton PC.
Copie-colle le rapport dans ta réponse : il est situé sur --> C:\_OTMoveIt\MovedFiles.
keygen : https://fr.wikipedia.org/wiki/Keygen
Au passage, j'ai une question : ta version de Windows XP n'est pas officielle je suppose ?
Toolbar S&D ne supprime pas les cracks (ce n'est pas sa fonction), il les signale seulement. Pour les supprimer, il faut le faire manuellement, mais tu peux utiliser ce programme pour le faire si tu veux :
Télécharge OTMoveIt (de Old_Timer) sur ton bureau...
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
# Double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
Copie le texte ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.
C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\I am\De la planŠte Mars\IAM (1991) - ...De La Plan‚te Mars - 06 - Crack.mp3 C:\DOCUME~1\Emilie\Mes documents\Ma musique\Rap francais\kerry james\Le Monde a Crack‚.mp3 C:\DOCUME~1\Emilie\Shared\_\Astro Hunter 3D Deluxe v2.1 (c) SB-Software Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\Crack.House.1989.WS.DVDRip.XviD-KVS.zip C:\DOCUME~1\Emilie\Shared\_\Gem Ball Ancient Legends v1.09 Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\Mahjong Escape Ancient Japan v1.0.0.1 Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MahJong Suite 2007 v4.0 KeyGen Only .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Canasta v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Cribbage v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Euchre And Ecarte v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Gin Rummy v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Pinochle And Bezique v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Piquet v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\MeggieSoft Rummy 500 v2007.70117 (c) MeggieSoft Games Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\Missile Commander XP v1.2 (c) SB-Software Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\PuzzleJoy v1.0.6 Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\Sam And Max Season 1 Culture Shock V1.0 CRACKFIX.zip C:\DOCUME~1\Emilie\Shared\_\Sudoku 9981 v4.01 Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\The Treasures of Montezuma v1.06 Incl Keygen .zip C:\DOCUME~1\Emilie\Shared\_\Zombie Smashers X2 v1.0 Incl Keygen .zip C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack.zip C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy\Recovery\WinXPServicePackCrack1.zip C:\DOCUME~1\Emilie\Shared
Clique sur MoveIt! pour lancer la suppression.
Lorsque un résultat apparaît dans le cadre Results, clique sur Exit et redémarre ton PC.
Copie-colle le rapport dans ta réponse : il est situé sur --> C:\_OTMoveIt\MovedFiles.