L'enfer des pop up - Help!!!
ano2345
Messages postés
18
Statut
Membre
-
E..T Messages postés 6565 Statut Contributeur -
E..T Messages postés 6565 Statut Contributeur -
Bonjour a tous,
Depuis peu, mon portable (qui fonctionne sous Windows XP avec IE 7.0) est infecte et des fenetres pop up n'arretent pas de s'ouvrir : quand je cherche un anti-virus une fenetre IE sans menu recouvre l'ecran et m'en propose, si je cherche un billet d'avion meme chose avec des sites de voyages, etc.
J'ai installe CCleaner, Avast et Spybot: Avast a vire 1 virus et qq spywares mais ca n'a pas regle mon probleme.
Apres ca, j'ai essaye Vundofix => 1 virus detecte et nettoye. Depuis, les pop up continuent sauf que le contenu a disparu (les fenetres pop up s'affichent et elles sont toutes blanches).
J'ai egalement fait tourne Navilog, catchme et hijackthis: j'ai colle tous les logs en dessous.
Est-ce que quelqu'un pourrait m'aider et jeter un coup d'oeil? Je n'ai absolument aucune idee de ce que veulent dire ces logs, et je ne sais plus quoi faire.
Un grand merci par avance.
Ano
Log Vundofix:
VundoFix V7.0.6
Scan started at 7:37:55 PM 11/9/2008
Listing files found while scanning....
C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll
Beginning removal...
Attempting to delete C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll
C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V7.0.6
Scan started at 8:10:43 PM 11/9/2008
Listing files found while scanning....
No infected files were found.
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:10 PM, on 11/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\documents and settings\ar.b\local settings\application data\isnpbtv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [isnpbtv] "c:\documents and settings\ar.b\local settings\application data\isnpbtv.exe" isnpbtv
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Depuis peu, mon portable (qui fonctionne sous Windows XP avec IE 7.0) est infecte et des fenetres pop up n'arretent pas de s'ouvrir : quand je cherche un anti-virus une fenetre IE sans menu recouvre l'ecran et m'en propose, si je cherche un billet d'avion meme chose avec des sites de voyages, etc.
J'ai installe CCleaner, Avast et Spybot: Avast a vire 1 virus et qq spywares mais ca n'a pas regle mon probleme.
Apres ca, j'ai essaye Vundofix => 1 virus detecte et nettoye. Depuis, les pop up continuent sauf que le contenu a disparu (les fenetres pop up s'affichent et elles sont toutes blanches).
J'ai egalement fait tourne Navilog, catchme et hijackthis: j'ai colle tous les logs en dessous.
Est-ce que quelqu'un pourrait m'aider et jeter un coup d'oeil? Je n'ai absolument aucune idee de ce que veulent dire ces logs, et je ne sais plus quoi faire.
Un grand merci par avance.
Ano
Log Vundofix:
VundoFix V7.0.6
Scan started at 7:37:55 PM 11/9/2008
Listing files found while scanning....
C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll
Beginning removal...
Attempting to delete C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll
C:\Windows\Installer\$PatchCache$\Managed\21E52B51F5E331C46A73E97CA25594E1\15.0.0\spsscls.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V7.0.6
Scan started at 8:10:43 PM 11/9/2008
Listing files found while scanning....
No infected files were found.
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:10 PM, on 11/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\documents and settings\ar.b\local settings\application data\isnpbtv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [isnpbtv] "c:\documents and settings\ar.b\local settings\application data\isnpbtv.exe" isnpbtv
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
A voir également:
- L'enfer des pop up - Help!!!
- Pop up mcafee - Accueil - Piratage
- Pop corn time - Télécharger - TV & Vidéo
- Serveur pop - Guide
- Augmenter débit freebox pop fibre ✓ - Forum Freebox
- Mode securise free pop - Forum Freebox
27 réponses
Salut,
Relance Navilog
# Sur le menu, choisis Désinfection automatique l'option 2
# Le fix va se mettre à travailler... sois patient!
# Cliques simplement sur OK si des fenêtres apparaissent.
Un rapport va être généré >> Envoi le
>>> Si ton bureau ne réapparait pas après le fix ce n'est rien ! <<<
Fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
@++
Relance Navilog
# Sur le menu, choisis Désinfection automatique l'option 2
# Le fix va se mettre à travailler... sois patient!
# Cliques simplement sur OK si des fenêtres apparaissent.
Un rapport va être généré >> Envoi le
>>> Si ton bureau ne réapparait pas après le fix ce n'est rien ! <<<
Fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
@++
Salut E..T,
Tout d'abord, merci pour ton aide.
J'ai lance l'option 2 de Navilog, et j'ai obtenu la rapport suivant:
Navilog - Option2
Clean Navipromo version 3.6.9 commencé le Mon 11/10/2008 à 9:07:47.17
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Administrator"
Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\Ar.B\locals~1\applic~1" *
* Suppression dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\startm~1\programs" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\startm~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Ar.B\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Ar.B\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\AR.B\startm~1\programs" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\startm~1\programs" ***
*** Suppression fichiers ***
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\AR.B\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
* Dans "C:\Documents and Settings\AR.B\locals~1\applic~1" *
isnpbtv.exe trouvé !
Copie isnpbtv.exe réalisée avec succès !
isnpbtv.exe supprimé !
isnpbtv.dat trouvé !
Copie isnpbtv.dat réalisée avec succès !
isnpbtv.dat supprimé !
isnpbtv_nav.dat trouvé !
Copie isnpbtv_nav.dat réalisée avec succès !
isnpbtv_nav.dat supprimé !
isnpbtv_navps.dat trouvé !
Copie isnpbtv_navps.dat réalisée avec succès !
isnpbtv_navps.dat supprimé !
C:\WINDOWS\prefetch\isnpbtv*.pf trouvé !
Copie C:\WINDOWS\prefetch\isnpbtv*.pf réalisée avec succès !
C:\WINDOWS\prefetch\isnpbtv*.pf supprimé !
* Dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat Montorgueil absent !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !
*** Nettoyage terminé le Mon 11/10/2008 à 9:15:48.53 ***
Ano
Tout d'abord, merci pour ton aide.
J'ai lance l'option 2 de Navilog, et j'ai obtenu la rapport suivant:
Navilog - Option2
Clean Navipromo version 3.6.9 commencé le Mon 11/10/2008 à 9:07:47.17
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Administrator"
Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\Ar.B\locals~1\applic~1" *
* Suppression dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\startm~1\programs" ***
*** Suppression dossiers dans "C:\Documents and Settings\All Users\startm~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Ar.B\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Ar.B\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\AR.B\startm~1\programs" ***
*** Suppression dossiers dans "C:\DOCUME~1\AR~1.B\startm~1\programs" ***
*** Suppression fichiers ***
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\AR.B\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
* Dans "C:\Documents and Settings\AR.B\locals~1\applic~1" *
isnpbtv.exe trouvé !
Copie isnpbtv.exe réalisée avec succès !
isnpbtv.exe supprimé !
isnpbtv.dat trouvé !
Copie isnpbtv.dat réalisée avec succès !
isnpbtv.dat supprimé !
isnpbtv_nav.dat trouvé !
Copie isnpbtv_nav.dat réalisée avec succès !
isnpbtv_nav.dat supprimé !
isnpbtv_navps.dat trouvé !
Copie isnpbtv_navps.dat réalisée avec succès !
isnpbtv_navps.dat supprimé !
C:\WINDOWS\prefetch\isnpbtv*.pf trouvé !
Copie C:\WINDOWS\prefetch\isnpbtv*.pf réalisée avec succès !
C:\WINDOWS\prefetch\isnpbtv*.pf supprimé !
* Dans "C:\DOCUME~1\AR~1.B\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat Montorgueil absent !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !
*** Nettoyage terminé le Mon 11/10/2008 à 9:15:48.53 ***
Ano
Impec ;)
Télécharge >> Lop S&D.exe << puis enregistres-le sur ton Bureau .
double-clic sur le fichier LopSD.exe suffira à lancer l'installation
Accepte le contat de licence
Créer le répertoire de destination, accepte en cliquant sur oui
Un raccourci sera créé sur ton Bureau.
Double clic dessus.
Choisis la langue f pour Français puis valide par Entrée.
Choisis l'option Recherche en saisissant 1 valides par Entrée.
Ton bureau va disparaitre c'est normal.
Patiente le temps du scan
A la fin du scan un rapport sera généré et s'ouvrira automatiquement dans le Bloc-Notes.
Copies-colles le contenu de ce rapport ici.
>>On le trouve aussi en %systemdrive%\LopR.txt
@++
Télécharge >> Lop S&D.exe << puis enregistres-le sur ton Bureau .
double-clic sur le fichier LopSD.exe suffira à lancer l'installation
Accepte le contat de licence
Créer le répertoire de destination, accepte en cliquant sur oui
Un raccourci sera créé sur ton Bureau.
Double clic dessus.
Choisis la langue f pour Français puis valide par Entrée.
Choisis l'option Recherche en saisissant 1 valides par Entrée.
Ton bureau va disparaitre c'est normal.
Patiente le temps du scan
A la fin du scan un rapport sera généré et s'ouvrira automatiquement dans le Bloc-Notes.
Copies-colles le contenu de ce rapport ici.
>>On le trouve aussi en %systemdrive%\LopR.txt
@++
J'ai fait ce que tu m'as dis. Le bureau n'a pas disparu et j'ai obtenu le rapport suivant:
LopSD Rapport:
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2500 @ 2.00GHz )
BIOS : Phoenix FirstBIOS(tm) Notebook Pro Version 2.0 for ThinkPad
USER : Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.6.6010 (Activated)
C:\ (Local Disk) - NTFS - Total:68 Go (Free:16 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Mon 11/10/2008| 9:35 )
--------------------\\ Listing des dossiers dans APPLIC~1
[01/17/2008|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
[01/28/2008|04:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
[10/23/2007|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[05/04/2008|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[07/18/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[07/18/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[04/30/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ATI
[05/05/2006|03:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Decisioneering
[11/28/2006|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[11/06/2006|02:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Insight Software Solutions
[04/12/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[01/17/2008|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lenovo
[10/07/2008|05:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logishrd
[06/29/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logitech
[10/26/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[10/26/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[05/01/2006|01:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MSScanAppDataDir
[05/10/2006|12:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Office Genuine Advantage
[04/17/2007|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC-Doctor
[08/09/2004|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[04/30/2008|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[11/09/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[05/15/2007|04:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> UIB
[04/24/2006|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[05/08/2008|07:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Adobe
[05/11/2008|09:30] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> AdobeUM
[07/18/2008|11:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Decisioneering
[06/09/2008|11:10] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Dev-Cpp
[04/12/2006|03:04] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InstallShield
[05/03/2008|07:51] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InterVideo
[06/15/2008|01:37] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> KeySafe
[04/13/2007|03:20] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lenovo
[10/04/2008|12:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> LinkedIn
[04/24/2006|03:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Macromedia
[10/17/2008|03:31] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Microsoft
[11/10/2008|12:29] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> OfficeUpdate12
[11/09/2008|07:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Skype
[11/09/2008|05:34] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> skypePM
[07/14/2008|10:26] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sonic
[05/01/2006|01:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ThinkVantage
[08/13/2008|03:58] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> vlc
[04/30/2008|03:46] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Winamp
[01/17/2008|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[01/23/2008|08:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> vlc
[05/01/2008|11:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Adobe
[05/06/2008|11:15] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Intel
[04/12/2006|03:01] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Lenovo
[08/18/2008|10:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[05/01/2006|01:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[04/11/2007|01:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/10/2008 09:16 AM][--a------] C:\WINDOWS\tasks\PMTask.job
[11/10/2008 09:11 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[10/15/2008|08:34] C:\Program Files\<DIR> Adobe
[04/24/2006|11:09] C:\Program Files\<DIR> Aladdin Systems
[11/09/2008|12:28] C:\Program Files\<DIR> Alwil Software
[04/12/2006|02:18] C:\Program Files\<DIR> Analog Devices
[07/18/2008|11:45] C:\Program Files\<DIR> Apple Software Update
[04/30/2008|10:39] C:\Program Files\<DIR> ATI Technologies
[04/24/2006|03:34] C:\Program Files\<DIR> BlitzMail
[10/06/2008|11:13] C:\Program Files\<DIR> Bonjour
[11/08/2008|07:25] C:\Program Files\<DIR> CCleaner
[10/23/2007|11:22] C:\Program Files\<DIR> Cisco Systems
[10/26/2008|10:31] C:\Program Files\<DIR> Common Files
[08/09/2004|12:51] C:\Program Files\<DIR> ComPlus Applications
[05/01/2006|12:01] C:\Program Files\<DIR> CONEXANT
[05/04/2008|09:10] C:\Program Files\<DIR> Cordless USB Phone
[05/05/2006|03:51] C:\Program Files\<DIR> Decisioneering
[02/06/2008|09:06] C:\Program Files\<DIR> Digital Line Detect
[04/24/2006|11:09] C:\Program Files\<DIR> DISKdata
[04/24/2006|03:34] C:\Program Files\<DIR> DNDedit
[11/07/2008|12:28] C:\Program Files\<DIR> eMule
[04/24/2006|11:10] C:\Program Files\<DIR> ERUNT
[08/18/2008|10:40] C:\Program Files\<DIR> ffdshow
[01/17/2008|04:54] C:\Program Files\<DIR> FileMaker
[08/18/2008|10:40] C:\Program Files\<DIR> FLVCodec
[08/09/2008|05:02] C:\Program Files\<DIR> Free Video Converter
[10/23/2007|03:08] C:\Program Files\<DIR> Frontline Systems
[04/24/2006|03:34] C:\Program Files\<DIR> Games
[11/28/2006|11:17] C:\Program Files\<DIR> Google
[07/17/2008|06:14] C:\Program Files\<DIR> Hewlett-Packard
[07/17/2008|06:11] C:\Program Files\<DIR> HP
[08/09/2008|01:59] C:\Program Files\<DIR> Huawei technologies
[04/12/2006|02:52] C:\Program Files\<DIR> IBM
[06/14/2006|08:16] C:\Program Files\<DIR> IBM ThinkVantage
[04/12/2006|02:55] C:\Program Files\<DIR> IBMTOOLS
[10/08/2008|11:55] C:\Program Files\<DIR> InstallShield Installation Information
[04/25/2006|12:09] C:\Program Files\<DIR> Intel
[10/26/2008|07:46] C:\Program Files\<DIR> Internet Explorer
[01/17/2008|08:49] C:\Program Files\<DIR> InterVideo
[07/18/2008|11:48] C:\Program Files\<DIR> iPod
[07/18/2008|11:49] C:\Program Files\<DIR> iTunes
[10/23/2007|01:20] C:\Program Files\<DIR> Java
[04/30/2008|10:14] C:\Program Files\<DIR> Lenovo
[09/20/2008|12:31] C:\Program Files\<DIR> Messenger
[04/24/2006|12:31] C:\Program Files\<DIR> Microsoft ActiveSync
[07/16/2008|05:27] C:\Program Files\<DIR> Microsoft Calculator Plus
[05/09/2007|01:41] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[08/09/2004|12:56] C:\Program Files\<DIR> microsoft frontpage
[04/19/2007|02:56] C:\Program Files\<DIR> Microsoft Office
[10/21/2008|10:47] C:\Program Files\<DIR> Microsoft Silverlight
[10/26/2008|10:14] C:\Program Files\<DIR> Microsoft SQL Server
[10/26/2008|11:00] C:\Program Files\<DIR> Microsoft Visual Studio
[10/26/2008|10:31] C:\Program Files\<DIR> Microsoft Visual Studio 9.0
[04/24/2006|12:37] C:\Program Files\<DIR> Microsoft Works
[10/26/2008|10:02] C:\Program Files\<DIR> Microsoft.NET
[09/20/2008|12:30] C:\Program Files\<DIR> Movie Maker
[11/10/2008|08:39] C:\Program Files\<DIR> Mozilla Firefox
[04/11/2007|12:06] C:\Program Files\<DIR> MSBuild
[05/15/2007|10:27] C:\Program Files\<DIR> MSECache
[04/24/2006|03:34] C:\Program Files\<DIR> Msgbox
[11/21/2006|11:28] C:\Program Files\<DIR> MSN
[08/09/2004|12:51] C:\Program Files\<DIR> MSN Gaming Zone
[10/20/2006|03:07] C:\Program Files\<DIR> MSXML 4.0
[05/15/2007|10:37] C:\Program Files\<DIR> MSXML 6.0
[10/23/2007|11:37] C:\Program Files\<DIR> Multimedia Center for Think Offerings
[04/24/2006|11:10] C:\Program Files\<DIR> MWSnap
[11/10/2008|09:15] C:\Program Files\<DIR> Navilog1
[09/20/2008|12:25] C:\Program Files\<DIR> NetMeeting
[04/24/2006|11:10] C:\Program Files\<DIR> NetPerSec
[02/06/2008|09:06] C:\Program Files\<DIR> NetWaiting
[11/09/2008|12:09] C:\Program Files\<DIR> NK2view
[04/24/2006|02:09] C:\Program Files\<DIR> OFFICE11
[08/09/2004|12:51] C:\Program Files\<DIR> Online Services
[10/23/2007|03:29] C:\Program Files\<DIR> Ookii.org Find As You Type 1.3
[04/24/2006|11:10] C:\Program Files\<DIR> OpenTarget
[09/20/2008|01:15] C:\Program Files\<DIR> Outlook Express
[10/23/2007|03:21] C:\Program Files\<DIR> Paint.NET
[05/16/2006|11:54] C:\Program Files\<DIR> PC Magazine Utilities
[04/30/2008|10:41] C:\Program Files\<DIR> PCDR5
[04/24/2006|02:16] C:\Program Files\<DIR> Pharos
[04/24/2006|11:10] C:\Program Files\<DIR> PrintFile
[01/17/2008|04:07] C:\Program Files\<DIR> Proxy Networks
[07/18/2008|11:48] C:\Program Files\<DIR> QuickTime
[04/11/2007|12:03] C:\Program Files\<DIR> Reference Assemblies
[05/01/2006|01:40] C:\Program Files\<DIR> RegEditX
[10/23/2007|03:11] C:\Program Files\<DIR> SensitivityToolkit
[04/24/2006|02:26] C:\Program Files\<DIR> SideCar
[04/30/2008|03:26] C:\Program Files\<DIR> Skype
[04/17/2007|07:38] C:\Program Files\<DIR> Sonic
[05/01/2006|05:00] C:\Program Files\<DIR> sprdprof
[01/17/2008|04:40] C:\Program Files\<DIR> SPSS
[11/09/2008|07:59] C:\Program Files\<DIR> Spybot - Search & Destroy
[04/24/2006|02:43] C:\Program Files\<DIR> SSH Communications Security
[06/01/2006|12:54] C:\Program Files\<DIR> StratX
[01/17/2008|01:17] C:\Program Files\<DIR> Symantec
[11/10/2008|09:12] C:\Program Files\<DIR> Symantec AntiVirus
[04/24/2006|10:03] C:\Program Files\<DIR> Symantec Client Security
[04/12/2006|02:17] C:\Program Files\<DIR> Synaptics
[04/17/2007|11:31] C:\Program Files\<DIR> SyncToy
[10/23/2007|11:37] C:\Program Files\<DIR> ThinkPad
[10/23/2007|12:27] C:\Program Files\<DIR> ThinkVantage
[10/23/2007|01:03] C:\Program Files\<DIR> ThinkVantage Fingerprint Software
[05/02/2006|11:07] C:\Program Files\<DIR> TreePlan
[11/09/2008|02:03] C:\Program Files\<DIR> Trend Micro
[08/09/2004|01:03] C:\Program Files\<DIR> Uninstall Information
[04/24/2006|11:11] C:\Program Files\<DIR> UPHClean
[10/23/2007|01:38] C:\Program Files\<DIR> VideoLAN
[04/30/2008|03:40] C:\Program Files\<DIR> Winamp
[10/23/2007|11:40] C:\Program Files\<DIR> Windows Desktop Search
[05/15/2007|10:27] C:\Program Files\<DIR> Windows Installer Clean Up
[04/24/2006|10:43] C:\Program Files\<DIR> Windows Media Connect
[01/11/2007|05:34] C:\Program Files\<DIR> Windows Media Connect 2
[09/20/2008|12:25] C:\Program Files\<DIR> Windows Media Player
[09/20/2008|12:25] C:\Program Files\<DIR> Windows NT
[08/09/2004|12:53] C:\Program Files\<DIR> WindowsUpdate
[11/08/2008|03:40] C:\Program Files\<DIR> WinZip
[08/09/2004|12:56] C:\Program Files\<DIR> xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[10/15/2008|08:35] C:\Program Files\Common Files\<DIR> Adobe
[05/04/2008|10:23] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[07/18/2008|11:44] C:\Program Files\Common Files\<DIR> Apple
[04/24/2006|02:12] C:\Program Files\Common Files\<DIR> Cisco Systems
[04/24/2006|12:30] C:\Program Files\Common Files\<DIR> DESIGNER
[10/23/2007|01:11] C:\Program Files\Common Files\<DIR> Deterministic Networks
[01/17/2008|04:07] C:\Program Files\Common Files\<DIR> Funk Software
[04/12/2006|02:33] C:\Program Files\Common Files\<DIR> InstallShield
[01/17/2008|08:49] C:\Program Files\Common Files\<DIR> InterVideo
[10/23/2007|01:19] C:\Program Files\Common Files\<DIR> Java
[04/24/2006|12:31] C:\Program Files\Common Files\<DIR> L&H
[02/06/2008|08:54] C:\Program Files\Common Files\<DIR> Lenovo
[01/17/2008|04:55] C:\Program Files\Common Files\<DIR> Macrovision Shared
[10/26/2008|10:59] C:\Program Files\Common Files\<DIR> Microsoft Shared
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> MSSoap
[01/17/2008|04:54] C:\Program Files\Common Files\<DIR> ODBC
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> Services
[04/30/2008|03:26] C:\Program Files\Common Files\<DIR> Skype
[10/08/2008|11:55] C:\Program Files\Common Files\<DIR> snpstd3
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> Sonic Shared
[08/09/2004|12:46] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> SureThing Shared
[01/17/2008|01:17] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/20/2008|12:24] C:\Program Files\Common Files\<DIR> System
[10/23/2007|01:01] C:\Program Files\Common Files\<DIR> ThinkVantage Fingerprint Software
[11/09/2008|01:28] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
--------------------\\ Process
( 85 Processes )
iexplore.exe ~ [PID:5860]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\AR~1.B\Cookies\administrator@advertising[2].txt
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 09:38:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\CuteFtp\cuteftpcrack.zip
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\FTPExpert\Crack_Ftp_Client.zip
[F:106][D:0]-> C:\DOCUME~1\AR~1.B\Cookies
[F:71][D:4]-> C:\DOCUME~1\AR~1.B\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled
1 - "C:\Lop SD\LopR_1.txt" - Mon 11/10/2008| 9:40 - Option : [1]
--------------------\\ Fin du rapport a 9:40:45
Ano
LopSD Rapport:
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2500 @ 2.00GHz )
BIOS : Phoenix FirstBIOS(tm) Notebook Pro Version 2.0 for ThinkPad
USER : Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.6.6010 (Activated)
C:\ (Local Disk) - NTFS - Total:68 Go (Free:16 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Mon 11/10/2008| 9:35 )
--------------------\\ Listing des dossiers dans APPLIC~1
[01/17/2008|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
[01/28/2008|04:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
[10/23/2007|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[05/04/2008|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[07/18/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[07/18/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[04/30/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ATI
[05/05/2006|03:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Decisioneering
[11/28/2006|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[11/06/2006|02:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Insight Software Solutions
[04/12/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[01/17/2008|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lenovo
[10/07/2008|05:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logishrd
[06/29/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logitech
[10/26/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[10/26/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[05/01/2006|01:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MSScanAppDataDir
[05/10/2006|12:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Office Genuine Advantage
[04/17/2007|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC-Doctor
[08/09/2004|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[04/30/2008|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[11/09/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[05/15/2007|04:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> UIB
[04/24/2006|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[05/08/2008|07:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Adobe
[05/11/2008|09:30] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> AdobeUM
[07/18/2008|11:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Decisioneering
[06/09/2008|11:10] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Dev-Cpp
[04/12/2006|03:04] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InstallShield
[05/03/2008|07:51] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InterVideo
[06/15/2008|01:37] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> KeySafe
[04/13/2007|03:20] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lenovo
[10/04/2008|12:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> LinkedIn
[04/24/2006|03:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Macromedia
[10/17/2008|03:31] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Microsoft
[11/10/2008|12:29] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> OfficeUpdate12
[11/09/2008|07:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Skype
[11/09/2008|05:34] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> skypePM
[07/14/2008|10:26] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sonic
[05/01/2006|01:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ThinkVantage
[08/13/2008|03:58] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> vlc
[04/30/2008|03:46] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Winamp
[01/17/2008|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[01/23/2008|08:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> vlc
[05/01/2008|11:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Adobe
[05/06/2008|11:15] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Intel
[04/12/2006|03:01] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Lenovo
[08/18/2008|10:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[05/01/2006|01:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[04/11/2007|01:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/10/2008 09:16 AM][--a------] C:\WINDOWS\tasks\PMTask.job
[11/10/2008 09:11 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[10/15/2008|08:34] C:\Program Files\<DIR> Adobe
[04/24/2006|11:09] C:\Program Files\<DIR> Aladdin Systems
[11/09/2008|12:28] C:\Program Files\<DIR> Alwil Software
[04/12/2006|02:18] C:\Program Files\<DIR> Analog Devices
[07/18/2008|11:45] C:\Program Files\<DIR> Apple Software Update
[04/30/2008|10:39] C:\Program Files\<DIR> ATI Technologies
[04/24/2006|03:34] C:\Program Files\<DIR> BlitzMail
[10/06/2008|11:13] C:\Program Files\<DIR> Bonjour
[11/08/2008|07:25] C:\Program Files\<DIR> CCleaner
[10/23/2007|11:22] C:\Program Files\<DIR> Cisco Systems
[10/26/2008|10:31] C:\Program Files\<DIR> Common Files
[08/09/2004|12:51] C:\Program Files\<DIR> ComPlus Applications
[05/01/2006|12:01] C:\Program Files\<DIR> CONEXANT
[05/04/2008|09:10] C:\Program Files\<DIR> Cordless USB Phone
[05/05/2006|03:51] C:\Program Files\<DIR> Decisioneering
[02/06/2008|09:06] C:\Program Files\<DIR> Digital Line Detect
[04/24/2006|11:09] C:\Program Files\<DIR> DISKdata
[04/24/2006|03:34] C:\Program Files\<DIR> DNDedit
[11/07/2008|12:28] C:\Program Files\<DIR> eMule
[04/24/2006|11:10] C:\Program Files\<DIR> ERUNT
[08/18/2008|10:40] C:\Program Files\<DIR> ffdshow
[01/17/2008|04:54] C:\Program Files\<DIR> FileMaker
[08/18/2008|10:40] C:\Program Files\<DIR> FLVCodec
[08/09/2008|05:02] C:\Program Files\<DIR> Free Video Converter
[10/23/2007|03:08] C:\Program Files\<DIR> Frontline Systems
[04/24/2006|03:34] C:\Program Files\<DIR> Games
[11/28/2006|11:17] C:\Program Files\<DIR> Google
[07/17/2008|06:14] C:\Program Files\<DIR> Hewlett-Packard
[07/17/2008|06:11] C:\Program Files\<DIR> HP
[08/09/2008|01:59] C:\Program Files\<DIR> Huawei technologies
[04/12/2006|02:52] C:\Program Files\<DIR> IBM
[06/14/2006|08:16] C:\Program Files\<DIR> IBM ThinkVantage
[04/12/2006|02:55] C:\Program Files\<DIR> IBMTOOLS
[10/08/2008|11:55] C:\Program Files\<DIR> InstallShield Installation Information
[04/25/2006|12:09] C:\Program Files\<DIR> Intel
[10/26/2008|07:46] C:\Program Files\<DIR> Internet Explorer
[01/17/2008|08:49] C:\Program Files\<DIR> InterVideo
[07/18/2008|11:48] C:\Program Files\<DIR> iPod
[07/18/2008|11:49] C:\Program Files\<DIR> iTunes
[10/23/2007|01:20] C:\Program Files\<DIR> Java
[04/30/2008|10:14] C:\Program Files\<DIR> Lenovo
[09/20/2008|12:31] C:\Program Files\<DIR> Messenger
[04/24/2006|12:31] C:\Program Files\<DIR> Microsoft ActiveSync
[07/16/2008|05:27] C:\Program Files\<DIR> Microsoft Calculator Plus
[05/09/2007|01:41] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[08/09/2004|12:56] C:\Program Files\<DIR> microsoft frontpage
[04/19/2007|02:56] C:\Program Files\<DIR> Microsoft Office
[10/21/2008|10:47] C:\Program Files\<DIR> Microsoft Silverlight
[10/26/2008|10:14] C:\Program Files\<DIR> Microsoft SQL Server
[10/26/2008|11:00] C:\Program Files\<DIR> Microsoft Visual Studio
[10/26/2008|10:31] C:\Program Files\<DIR> Microsoft Visual Studio 9.0
[04/24/2006|12:37] C:\Program Files\<DIR> Microsoft Works
[10/26/2008|10:02] C:\Program Files\<DIR> Microsoft.NET
[09/20/2008|12:30] C:\Program Files\<DIR> Movie Maker
[11/10/2008|08:39] C:\Program Files\<DIR> Mozilla Firefox
[04/11/2007|12:06] C:\Program Files\<DIR> MSBuild
[05/15/2007|10:27] C:\Program Files\<DIR> MSECache
[04/24/2006|03:34] C:\Program Files\<DIR> Msgbox
[11/21/2006|11:28] C:\Program Files\<DIR> MSN
[08/09/2004|12:51] C:\Program Files\<DIR> MSN Gaming Zone
[10/20/2006|03:07] C:\Program Files\<DIR> MSXML 4.0
[05/15/2007|10:37] C:\Program Files\<DIR> MSXML 6.0
[10/23/2007|11:37] C:\Program Files\<DIR> Multimedia Center for Think Offerings
[04/24/2006|11:10] C:\Program Files\<DIR> MWSnap
[11/10/2008|09:15] C:\Program Files\<DIR> Navilog1
[09/20/2008|12:25] C:\Program Files\<DIR> NetMeeting
[04/24/2006|11:10] C:\Program Files\<DIR> NetPerSec
[02/06/2008|09:06] C:\Program Files\<DIR> NetWaiting
[11/09/2008|12:09] C:\Program Files\<DIR> NK2view
[04/24/2006|02:09] C:\Program Files\<DIR> OFFICE11
[08/09/2004|12:51] C:\Program Files\<DIR> Online Services
[10/23/2007|03:29] C:\Program Files\<DIR> Ookii.org Find As You Type 1.3
[04/24/2006|11:10] C:\Program Files\<DIR> OpenTarget
[09/20/2008|01:15] C:\Program Files\<DIR> Outlook Express
[10/23/2007|03:21] C:\Program Files\<DIR> Paint.NET
[05/16/2006|11:54] C:\Program Files\<DIR> PC Magazine Utilities
[04/30/2008|10:41] C:\Program Files\<DIR> PCDR5
[04/24/2006|02:16] C:\Program Files\<DIR> Pharos
[04/24/2006|11:10] C:\Program Files\<DIR> PrintFile
[01/17/2008|04:07] C:\Program Files\<DIR> Proxy Networks
[07/18/2008|11:48] C:\Program Files\<DIR> QuickTime
[04/11/2007|12:03] C:\Program Files\<DIR> Reference Assemblies
[05/01/2006|01:40] C:\Program Files\<DIR> RegEditX
[10/23/2007|03:11] C:\Program Files\<DIR> SensitivityToolkit
[04/24/2006|02:26] C:\Program Files\<DIR> SideCar
[04/30/2008|03:26] C:\Program Files\<DIR> Skype
[04/17/2007|07:38] C:\Program Files\<DIR> Sonic
[05/01/2006|05:00] C:\Program Files\<DIR> sprdprof
[01/17/2008|04:40] C:\Program Files\<DIR> SPSS
[11/09/2008|07:59] C:\Program Files\<DIR> Spybot - Search & Destroy
[04/24/2006|02:43] C:\Program Files\<DIR> SSH Communications Security
[06/01/2006|12:54] C:\Program Files\<DIR> StratX
[01/17/2008|01:17] C:\Program Files\<DIR> Symantec
[11/10/2008|09:12] C:\Program Files\<DIR> Symantec AntiVirus
[04/24/2006|10:03] C:\Program Files\<DIR> Symantec Client Security
[04/12/2006|02:17] C:\Program Files\<DIR> Synaptics
[04/17/2007|11:31] C:\Program Files\<DIR> SyncToy
[10/23/2007|11:37] C:\Program Files\<DIR> ThinkPad
[10/23/2007|12:27] C:\Program Files\<DIR> ThinkVantage
[10/23/2007|01:03] C:\Program Files\<DIR> ThinkVantage Fingerprint Software
[05/02/2006|11:07] C:\Program Files\<DIR> TreePlan
[11/09/2008|02:03] C:\Program Files\<DIR> Trend Micro
[08/09/2004|01:03] C:\Program Files\<DIR> Uninstall Information
[04/24/2006|11:11] C:\Program Files\<DIR> UPHClean
[10/23/2007|01:38] C:\Program Files\<DIR> VideoLAN
[04/30/2008|03:40] C:\Program Files\<DIR> Winamp
[10/23/2007|11:40] C:\Program Files\<DIR> Windows Desktop Search
[05/15/2007|10:27] C:\Program Files\<DIR> Windows Installer Clean Up
[04/24/2006|10:43] C:\Program Files\<DIR> Windows Media Connect
[01/11/2007|05:34] C:\Program Files\<DIR> Windows Media Connect 2
[09/20/2008|12:25] C:\Program Files\<DIR> Windows Media Player
[09/20/2008|12:25] C:\Program Files\<DIR> Windows NT
[08/09/2004|12:53] C:\Program Files\<DIR> WindowsUpdate
[11/08/2008|03:40] C:\Program Files\<DIR> WinZip
[08/09/2004|12:56] C:\Program Files\<DIR> xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[10/15/2008|08:35] C:\Program Files\Common Files\<DIR> Adobe
[05/04/2008|10:23] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[07/18/2008|11:44] C:\Program Files\Common Files\<DIR> Apple
[04/24/2006|02:12] C:\Program Files\Common Files\<DIR> Cisco Systems
[04/24/2006|12:30] C:\Program Files\Common Files\<DIR> DESIGNER
[10/23/2007|01:11] C:\Program Files\Common Files\<DIR> Deterministic Networks
[01/17/2008|04:07] C:\Program Files\Common Files\<DIR> Funk Software
[04/12/2006|02:33] C:\Program Files\Common Files\<DIR> InstallShield
[01/17/2008|08:49] C:\Program Files\Common Files\<DIR> InterVideo
[10/23/2007|01:19] C:\Program Files\Common Files\<DIR> Java
[04/24/2006|12:31] C:\Program Files\Common Files\<DIR> L&H
[02/06/2008|08:54] C:\Program Files\Common Files\<DIR> Lenovo
[01/17/2008|04:55] C:\Program Files\Common Files\<DIR> Macrovision Shared
[10/26/2008|10:59] C:\Program Files\Common Files\<DIR> Microsoft Shared
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> MSSoap
[01/17/2008|04:54] C:\Program Files\Common Files\<DIR> ODBC
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> Services
[04/30/2008|03:26] C:\Program Files\Common Files\<DIR> Skype
[10/08/2008|11:55] C:\Program Files\Common Files\<DIR> snpstd3
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> Sonic Shared
[08/09/2004|12:46] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> SureThing Shared
[01/17/2008|01:17] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/20/2008|12:24] C:\Program Files\Common Files\<DIR> System
[10/23/2007|01:01] C:\Program Files\Common Files\<DIR> ThinkVantage Fingerprint Software
[11/09/2008|01:28] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
--------------------\\ Process
( 85 Processes )
iexplore.exe ~ [PID:5860]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\AR~1.B\Cookies\administrator@advertising[2].txt
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 09:38:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\CuteFtp\cuteftpcrack.zip
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\FTPExpert\Crack_Ftp_Client.zip
[F:106][D:0]-> C:\DOCUME~1\AR~1.B\Cookies
[F:71][D:4]-> C:\DOCUME~1\AR~1.B\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled
1 - "C:\Lop SD\LopR_1.txt" - Mon 11/10/2008| 9:40 - Option : [1]
--------------------\\ Fin du rapport a 9:40:45
Ano
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Ouep,
Refais la même chose mais la tu choisis le choix 2
Laisse travailler le pc
Une fois le nettoyage fini ,une recherche sera relancée et un rapport
s'ouvrira automatiquement dans le Bloc-Notes.
Copies-colles le contenu de ce rapport sur le forum.
Puis met un nouveau rapport hijack this.
@+
Refais la même chose mais la tu choisis le choix 2
Laisse travailler le pc
Une fois le nettoyage fini ,une recherche sera relancée et un rapport
s'ouvrira automatiquement dans le Bloc-Notes.
Copies-colles le contenu de ce rapport sur le forum.
Puis met un nouveau rapport hijack this.
@+
Salut E..T,
J'ai relance LopSD.exe avec l'option 2, mais j'ai l'impression qu'il na rien trouve de suspect
Lop SD - Option2:
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2500 @ 2.00GHz )
BIOS : Phoenix FirstBIOS(tm) Notebook Pro Version 2.0 for ThinkPad
USER : Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.6.6010 (Activated)
C:\ (Local Disk) - NTFS - Total:68 Go (Free:16 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [2] ( Mon 11/10/2008|10:04 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\AR~1.B\Cookies\administrator@advertising[2].txt
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[01/17/2008|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
[01/28/2008|04:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
[10/23/2007|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[05/04/2008|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[07/18/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[07/18/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[04/30/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ATI
[05/05/2006|03:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Decisioneering
[11/28/2006|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[11/06/2006|02:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Insight Software Solutions
[04/12/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[01/17/2008|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lenovo
[10/07/2008|05:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logishrd
[06/29/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logitech
[10/26/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[10/26/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[05/01/2006|01:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MSScanAppDataDir
[05/10/2006|12:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Office Genuine Advantage
[04/17/2007|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC-Doctor
[08/09/2004|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[04/30/2008|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[11/09/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[05/15/2007|04:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> UIB
[04/24/2006|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[05/08/2008|07:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Adobe
[05/11/2008|09:30] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> AdobeUM
[07/18/2008|11:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Decisioneering
[06/09/2008|11:10] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Dev-Cpp
[04/12/2006|03:04] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InstallShield
[05/03/2008|07:51] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InterVideo
[06/15/2008|01:37] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> KeySafe
[04/13/2007|03:20] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lenovo
[10/04/2008|12:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> LinkedIn
[04/24/2006|03:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Macromedia
[10/17/2008|03:31] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Microsoft
[11/10/2008|12:29] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> OfficeUpdate12
[11/09/2008|07:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Skype
[11/09/2008|05:34] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> skypePM
[07/14/2008|10:26] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sonic
[05/01/2006|01:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ThinkVantage
[08/13/2008|03:58] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> vlc
[04/30/2008|03:46] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Winamp
[01/17/2008|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[01/23/2008|08:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> vlc
[05/01/2008|11:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Adobe
[05/06/2008|11:15] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Intel
[04/12/2006|03:01] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Lenovo
[08/18/2008|10:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[05/01/2006|01:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[04/11/2007|01:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/10/2008 10:00 AM][--a------] C:\WINDOWS\tasks\PMTask.job
[11/10/2008 09:11 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[10/15/2008|08:34] C:\Program Files\<DIR> Adobe
[04/24/2006|11:09] C:\Program Files\<DIR> Aladdin Systems
[11/09/2008|12:28] C:\Program Files\<DIR> Alwil Software
[04/12/2006|02:18] C:\Program Files\<DIR> Analog Devices
[07/18/2008|11:45] C:\Program Files\<DIR> Apple Software Update
[04/30/2008|10:39] C:\Program Files\<DIR> ATI Technologies
[04/24/2006|03:34] C:\Program Files\<DIR> BlitzMail
[10/06/2008|11:13] C:\Program Files\<DIR> Bonjour
[11/08/2008|07:25] C:\Program Files\<DIR> CCleaner
[10/23/2007|11:22] C:\Program Files\<DIR> Cisco Systems
[10/26/2008|10:31] C:\Program Files\<DIR> Common Files
[08/09/2004|12:51] C:\Program Files\<DIR> ComPlus Applications
[05/01/2006|12:01] C:\Program Files\<DIR> CONEXANT
[05/04/2008|09:10] C:\Program Files\<DIR> Cordless USB Phone
[05/05/2006|03:51] C:\Program Files\<DIR> Decisioneering
[02/06/2008|09:06] C:\Program Files\<DIR> Digital Line Detect
[04/24/2006|11:09] C:\Program Files\<DIR> DISKdata
[04/24/2006|03:34] C:\Program Files\<DIR> DNDedit
[11/07/2008|12:28] C:\Program Files\<DIR> eMule
[04/24/2006|11:10] C:\Program Files\<DIR> ERUNT
[08/18/2008|10:40] C:\Program Files\<DIR> ffdshow
[01/17/2008|04:54] C:\Program Files\<DIR> FileMaker
[08/18/2008|10:40] C:\Program Files\<DIR> FLVCodec
[08/09/2008|05:02] C:\Program Files\<DIR> Free Video Converter
[10/23/2007|03:08] C:\Program Files\<DIR> Frontline Systems
[04/24/2006|03:34] C:\Program Files\<DIR> Games
[11/28/2006|11:17] C:\Program Files\<DIR> Google
[07/17/2008|06:14] C:\Program Files\<DIR> Hewlett-Packard
[07/17/2008|06:11] C:\Program Files\<DIR> HP
[08/09/2008|01:59] C:\Program Files\<DIR> Huawei technologies
[04/12/2006|02:52] C:\Program Files\<DIR> IBM
[06/14/2006|08:16] C:\Program Files\<DIR> IBM ThinkVantage
[04/12/2006|02:55] C:\Program Files\<DIR> IBMTOOLS
[10/08/2008|11:55] C:\Program Files\<DIR> InstallShield Installation Information
[04/25/2006|12:09] C:\Program Files\<DIR> Intel
[10/26/2008|07:46] C:\Program Files\<DIR> Internet Explorer
[01/17/2008|08:49] C:\Program Files\<DIR> InterVideo
[07/18/2008|11:48] C:\Program Files\<DIR> iPod
[07/18/2008|11:49] C:\Program Files\<DIR> iTunes
[10/23/2007|01:20] C:\Program Files\<DIR> Java
[04/30/2008|10:14] C:\Program Files\<DIR> Lenovo
[09/20/2008|12:31] C:\Program Files\<DIR> Messenger
[04/24/2006|12:31] C:\Program Files\<DIR> Microsoft ActiveSync
[07/16/2008|05:27] C:\Program Files\<DIR> Microsoft Calculator Plus
[05/09/2007|01:41] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[08/09/2004|12:56] C:\Program Files\<DIR> microsoft frontpage
[04/19/2007|02:56] C:\Program Files\<DIR> Microsoft Office
[10/21/2008|10:47] C:\Program Files\<DIR> Microsoft Silverlight
[10/26/2008|10:14] C:\Program Files\<DIR> Microsoft SQL Server
[10/26/2008|11:00] C:\Program Files\<DIR> Microsoft Visual Studio
[10/26/2008|10:31] C:\Program Files\<DIR> Microsoft Visual Studio 9.0
[04/24/2006|12:37] C:\Program Files\<DIR> Microsoft Works
[10/26/2008|10:02] C:\Program Files\<DIR> Microsoft.NET
[09/20/2008|12:30] C:\Program Files\<DIR> Movie Maker
[11/10/2008|09:51] C:\Program Files\<DIR> Mozilla Firefox
[04/11/2007|12:06] C:\Program Files\<DIR> MSBuild
[05/15/2007|10:27] C:\Program Files\<DIR> MSECache
[04/24/2006|03:34] C:\Program Files\<DIR> Msgbox
[11/21/2006|11:28] C:\Program Files\<DIR> MSN
[08/09/2004|12:51] C:\Program Files\<DIR> MSN Gaming Zone
[10/20/2006|03:07] C:\Program Files\<DIR> MSXML 4.0
[05/15/2007|10:37] C:\Program Files\<DIR> MSXML 6.0
[10/23/2007|11:37] C:\Program Files\<DIR> Multimedia Center for Think Offerings
[04/24/2006|11:10] C:\Program Files\<DIR> MWSnap
[11/10/2008|10:04] C:\Program Files\<DIR> Navilog1
[09/20/2008|12:25] C:\Program Files\<DIR> NetMeeting
[04/24/2006|11:10] C:\Program Files\<DIR> NetPerSec
[02/06/2008|09:06] C:\Program Files\<DIR> NetWaiting
[11/09/2008|12:09] C:\Program Files\<DIR> NK2view
[04/24/2006|02:09] C:\Program Files\<DIR> OFFICE11
[08/09/2004|12:51] C:\Program Files\<DIR> Online Services
[10/23/2007|03:29] C:\Program Files\<DIR> Ookii.org Find As You Type 1.3
[04/24/2006|11:10] C:\Program Files\<DIR> OpenTarget
[09/20/2008|01:15] C:\Program Files\<DIR> Outlook Express
[10/23/2007|03:21] C:\Program Files\<DIR> Paint.NET
[05/16/2006|11:54] C:\Program Files\<DIR> PC Magazine Utilities
[04/30/2008|10:41] C:\Program Files\<DIR> PCDR5
[04/24/2006|02:16] C:\Program Files\<DIR> Pharos
[04/24/2006|11:10] C:\Program Files\<DIR> PrintFile
[01/17/2008|04:07] C:\Program Files\<DIR> Proxy Networks
[07/18/2008|11:48] C:\Program Files\<DIR> QuickTime
[04/11/2007|12:03] C:\Program Files\<DIR> Reference Assemblies
[05/01/2006|01:40] C:\Program Files\<DIR> RegEditX
[10/23/2007|03:11] C:\Program Files\<DIR> SensitivityToolkit
[04/24/2006|02:26] C:\Program Files\<DIR> SideCar
[04/30/2008|03:26] C:\Program Files\<DIR> Skype
[04/17/2007|07:38] C:\Program Files\<DIR> Sonic
[05/01/2006|05:00] C:\Program Files\<DIR> sprdprof
[01/17/2008|04:40] C:\Program Files\<DIR> SPSS
[11/09/2008|07:59] C:\Program Files\<DIR> Spybot - Search & Destroy
[04/24/2006|02:43] C:\Program Files\<DIR> SSH Communications Security
[06/01/2006|12:54] C:\Program Files\<DIR> StratX
[01/17/2008|01:17] C:\Program Files\<DIR> Symantec
[11/10/2008|09:12] C:\Program Files\<DIR> Symantec AntiVirus
[04/24/2006|10:03] C:\Program Files\<DIR> Symantec Client Security
[04/12/2006|02:17] C:\Program Files\<DIR> Synaptics
[04/17/2007|11:31] C:\Program Files\<DIR> SyncToy
[10/23/2007|11:37] C:\Program Files\<DIR> ThinkPad
[10/23/2007|12:27] C:\Program Files\<DIR> ThinkVantage
[10/23/2007|01:03] C:\Program Files\<DIR> ThinkVantage Fingerprint Software
[05/02/2006|11:07] C:\Program Files\<DIR> TreePlan
[11/09/2008|02:03] C:\Program Files\<DIR> Trend Micro
[08/09/2004|01:03] C:\Program Files\<DIR> Uninstall Information
[04/24/2006|11:11] C:\Program Files\<DIR> UPHClean
[10/23/2007|01:38] C:\Program Files\<DIR> VideoLAN
[04/30/2008|03:40] C:\Program Files\<DIR> Winamp
[10/23/2007|11:40] C:\Program Files\<DIR> Windows Desktop Search
[05/15/2007|10:27] C:\Program Files\<DIR> Windows Installer Clean Up
[04/24/2006|10:43] C:\Program Files\<DIR> Windows Media Connect
[01/11/2007|05:34] C:\Program Files\<DIR> Windows Media Connect 2
[09/20/2008|12:25] C:\Program Files\<DIR> Windows Media Player
[09/20/2008|12:25] C:\Program Files\<DIR> Windows NT
[08/09/2004|12:53] C:\Program Files\<DIR> WindowsUpdate
[11/08/2008|03:40] C:\Program Files\<DIR> WinZip
[08/09/2004|12:56] C:\Program Files\<DIR> xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[10/15/2008|08:35] C:\Program Files\Common Files\<DIR> Adobe
[05/04/2008|10:23] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[07/18/2008|11:44] C:\Program Files\Common Files\<DIR> Apple
[04/24/2006|02:12] C:\Program Files\Common Files\<DIR> Cisco Systems
[04/24/2006|12:30] C:\Program Files\Common Files\<DIR> DESIGNER
[10/23/2007|01:11] C:\Program Files\Common Files\<DIR> Deterministic Networks
[01/17/2008|04:07] C:\Program Files\Common Files\<DIR> Funk Software
[04/12/2006|02:33] C:\Program Files\Common Files\<DIR> InstallShield
[01/17/2008|08:49] C:\Program Files\Common Files\<DIR> InterVideo
[10/23/2007|01:19] C:\Program Files\Common Files\<DIR> Java
[04/24/2006|12:31] C:\Program Files\Common Files\<DIR> L&H
[02/06/2008|08:54] C:\Program Files\Common Files\<DIR> Lenovo
[01/17/2008|04:55] C:\Program Files\Common Files\<DIR> Macrovision Shared
[10/26/2008|10:59] C:\Program Files\Common Files\<DIR> Microsoft Shared
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> MSSoap
[01/17/2008|04:54] C:\Program Files\Common Files\<DIR> ODBC
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> Services
[04/30/2008|03:26] C:\Program Files\Common Files\<DIR> Skype
[10/08/2008|11:55] C:\Program Files\Common Files\<DIR> snpstd3
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> Sonic Shared
[08/09/2004|12:46] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> SureThing Shared
[01/17/2008|01:17] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/20/2008|12:24] C:\Program Files\Common Files\<DIR> System
[10/23/2007|01:01] C:\Program Files\Common Files\<DIR> ThinkVantage Fingerprint Software
[11/09/2008|01:28] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
--------------------\\ Process
( 85 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 10:06:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\CuteFtp\cuteftpcrack.zip
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\FTPExpert\Crack_Ftp_Client.zip
[F:1][D:2]-> C:\DOCUME~1\AR~1.B\LOCALS~1\Temp
[F:105][D:0]-> C:\DOCUME~1\AR~1.B\Cookies
[F:84][D:4]-> C:\DOCUME~1\AR~1.B\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled
1 - "C:\Lop SD\LopR_1.txt" - Mon 11/10/2008| 9:40 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Mon 11/10/2008|10:07 - Option : [2]
--------------------\\ Fin du rapport a 10:07:29
Et voici le rapport Hijackthis que j'ai lance apres ca:
Hijackthis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:15 AM, on 11/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
J'ai relance LopSD.exe avec l'option 2, mais j'ai l'impression qu'il na rien trouve de suspect
Lop SD - Option2:
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2500 @ 2.00GHz )
BIOS : Phoenix FirstBIOS(tm) Notebook Pro Version 2.0 for ThinkPad
USER : Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.6.6010 (Activated)
C:\ (Local Disk) - NTFS - Total:68 Go (Free:16 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [2] ( Mon 11/10/2008|10:04 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\AR~1.B\Cookies\administrator@advertising[2].txt
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[01/17/2008|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
[01/28/2008|04:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
[10/23/2007|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[05/04/2008|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[07/18/2008|11:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[07/18/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[04/30/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ATI
[05/05/2006|03:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Decisioneering
[11/28/2006|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[11/06/2006|02:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Insight Software Solutions
[04/12/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[01/17/2008|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Lenovo
[10/07/2008|05:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logishrd
[06/29/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Logitech
[10/26/2008|08:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[10/26/2008|10:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[05/01/2006|01:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> MSScanAppDataDir
[05/10/2006|12:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Office Genuine Advantage
[04/17/2007|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC-Doctor
[08/09/2004|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SBSI
[04/30/2008|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[11/09/2008|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[05/15/2007|04:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[06/14/2006|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> UIB
[04/24/2006|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[05/08/2008|07:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Adobe
[05/11/2008|09:30] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> AdobeUM
[07/18/2008|11:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Decisioneering
[06/09/2008|11:10] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Dev-Cpp
[04/12/2006|03:04] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InstallShield
[05/03/2008|07:51] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> InterVideo
[06/15/2008|01:37] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> KeySafe
[04/13/2007|03:20] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Lenovo
[10/04/2008|12:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> LinkedIn
[04/24/2006|03:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Macromedia
[10/17/2008|03:31] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Microsoft
[11/10/2008|12:29] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> OfficeUpdate12
[11/09/2008|07:49] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Skype
[11/09/2008|05:34] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> skypePM
[07/14/2008|10:26] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sonic
[05/01/2006|01:23] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> ThinkVantage
[08/13/2008|03:58] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> vlc
[04/30/2008|03:46] C:\DOCUME~1\AR~1.B\APPLIC~1\<DIR> Winamp
[01/17/2008|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[11/28/2006|10:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AdobeUM
[05/01/2006|01:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Apple Computer
[10/23/2007|01:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ATI
[04/24/2006|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Cisco
[05/05/2006|03:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Decisioneering
[04/12/2006|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Google
[05/01/2006|05:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Help
[04/12/2006|02:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> IBM
[04/24/2006|11:00] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[04/17/2007|07:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InstallShield
[04/13/2007|03:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lavasoft
[01/17/2008|03:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Leadertech
[05/16/2007|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Lenovo
[04/24/2006|03:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[01/23/2008|08:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[04/24/2006|03:06] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Mozilla
[11/21/2006|11:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MSNInstaller
[11/06/2006|02:40] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> MyDataZone
[05/25/2007|09:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> OfficeUpdate12
[05/01/2006|01:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SSH
[04/24/2006|02:32] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Sun
[04/12/2006|02:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Symantec
[05/25/2007|09:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Talkback
[04/22/2006|04:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> ThinkVantage
[10/23/2007|01:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> vlc
[05/01/2008|11:08] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Adobe
[05/06/2008|11:15] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Intel
[04/12/2006|03:01] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Lenovo
[08/18/2008|10:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Macromedia
[05/01/2006|01:09] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[04/11/2007|01:42] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[11/10/2008 10:00 AM][--a------] C:\WINDOWS\tasks\PMTask.job
[11/10/2008 09:11 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[10/15/2008|08:34] C:\Program Files\<DIR> Adobe
[04/24/2006|11:09] C:\Program Files\<DIR> Aladdin Systems
[11/09/2008|12:28] C:\Program Files\<DIR> Alwil Software
[04/12/2006|02:18] C:\Program Files\<DIR> Analog Devices
[07/18/2008|11:45] C:\Program Files\<DIR> Apple Software Update
[04/30/2008|10:39] C:\Program Files\<DIR> ATI Technologies
[04/24/2006|03:34] C:\Program Files\<DIR> BlitzMail
[10/06/2008|11:13] C:\Program Files\<DIR> Bonjour
[11/08/2008|07:25] C:\Program Files\<DIR> CCleaner
[10/23/2007|11:22] C:\Program Files\<DIR> Cisco Systems
[10/26/2008|10:31] C:\Program Files\<DIR> Common Files
[08/09/2004|12:51] C:\Program Files\<DIR> ComPlus Applications
[05/01/2006|12:01] C:\Program Files\<DIR> CONEXANT
[05/04/2008|09:10] C:\Program Files\<DIR> Cordless USB Phone
[05/05/2006|03:51] C:\Program Files\<DIR> Decisioneering
[02/06/2008|09:06] C:\Program Files\<DIR> Digital Line Detect
[04/24/2006|11:09] C:\Program Files\<DIR> DISKdata
[04/24/2006|03:34] C:\Program Files\<DIR> DNDedit
[11/07/2008|12:28] C:\Program Files\<DIR> eMule
[04/24/2006|11:10] C:\Program Files\<DIR> ERUNT
[08/18/2008|10:40] C:\Program Files\<DIR> ffdshow
[01/17/2008|04:54] C:\Program Files\<DIR> FileMaker
[08/18/2008|10:40] C:\Program Files\<DIR> FLVCodec
[08/09/2008|05:02] C:\Program Files\<DIR> Free Video Converter
[10/23/2007|03:08] C:\Program Files\<DIR> Frontline Systems
[04/24/2006|03:34] C:\Program Files\<DIR> Games
[11/28/2006|11:17] C:\Program Files\<DIR> Google
[07/17/2008|06:14] C:\Program Files\<DIR> Hewlett-Packard
[07/17/2008|06:11] C:\Program Files\<DIR> HP
[08/09/2008|01:59] C:\Program Files\<DIR> Huawei technologies
[04/12/2006|02:52] C:\Program Files\<DIR> IBM
[06/14/2006|08:16] C:\Program Files\<DIR> IBM ThinkVantage
[04/12/2006|02:55] C:\Program Files\<DIR> IBMTOOLS
[10/08/2008|11:55] C:\Program Files\<DIR> InstallShield Installation Information
[04/25/2006|12:09] C:\Program Files\<DIR> Intel
[10/26/2008|07:46] C:\Program Files\<DIR> Internet Explorer
[01/17/2008|08:49] C:\Program Files\<DIR> InterVideo
[07/18/2008|11:48] C:\Program Files\<DIR> iPod
[07/18/2008|11:49] C:\Program Files\<DIR> iTunes
[10/23/2007|01:20] C:\Program Files\<DIR> Java
[04/30/2008|10:14] C:\Program Files\<DIR> Lenovo
[09/20/2008|12:31] C:\Program Files\<DIR> Messenger
[04/24/2006|12:31] C:\Program Files\<DIR> Microsoft ActiveSync
[07/16/2008|05:27] C:\Program Files\<DIR> Microsoft Calculator Plus
[05/09/2007|01:41] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[08/09/2004|12:56] C:\Program Files\<DIR> microsoft frontpage
[04/19/2007|02:56] C:\Program Files\<DIR> Microsoft Office
[10/21/2008|10:47] C:\Program Files\<DIR> Microsoft Silverlight
[10/26/2008|10:14] C:\Program Files\<DIR> Microsoft SQL Server
[10/26/2008|11:00] C:\Program Files\<DIR> Microsoft Visual Studio
[10/26/2008|10:31] C:\Program Files\<DIR> Microsoft Visual Studio 9.0
[04/24/2006|12:37] C:\Program Files\<DIR> Microsoft Works
[10/26/2008|10:02] C:\Program Files\<DIR> Microsoft.NET
[09/20/2008|12:30] C:\Program Files\<DIR> Movie Maker
[11/10/2008|09:51] C:\Program Files\<DIR> Mozilla Firefox
[04/11/2007|12:06] C:\Program Files\<DIR> MSBuild
[05/15/2007|10:27] C:\Program Files\<DIR> MSECache
[04/24/2006|03:34] C:\Program Files\<DIR> Msgbox
[11/21/2006|11:28] C:\Program Files\<DIR> MSN
[08/09/2004|12:51] C:\Program Files\<DIR> MSN Gaming Zone
[10/20/2006|03:07] C:\Program Files\<DIR> MSXML 4.0
[05/15/2007|10:37] C:\Program Files\<DIR> MSXML 6.0
[10/23/2007|11:37] C:\Program Files\<DIR> Multimedia Center for Think Offerings
[04/24/2006|11:10] C:\Program Files\<DIR> MWSnap
[11/10/2008|10:04] C:\Program Files\<DIR> Navilog1
[09/20/2008|12:25] C:\Program Files\<DIR> NetMeeting
[04/24/2006|11:10] C:\Program Files\<DIR> NetPerSec
[02/06/2008|09:06] C:\Program Files\<DIR> NetWaiting
[11/09/2008|12:09] C:\Program Files\<DIR> NK2view
[04/24/2006|02:09] C:\Program Files\<DIR> OFFICE11
[08/09/2004|12:51] C:\Program Files\<DIR> Online Services
[10/23/2007|03:29] C:\Program Files\<DIR> Ookii.org Find As You Type 1.3
[04/24/2006|11:10] C:\Program Files\<DIR> OpenTarget
[09/20/2008|01:15] C:\Program Files\<DIR> Outlook Express
[10/23/2007|03:21] C:\Program Files\<DIR> Paint.NET
[05/16/2006|11:54] C:\Program Files\<DIR> PC Magazine Utilities
[04/30/2008|10:41] C:\Program Files\<DIR> PCDR5
[04/24/2006|02:16] C:\Program Files\<DIR> Pharos
[04/24/2006|11:10] C:\Program Files\<DIR> PrintFile
[01/17/2008|04:07] C:\Program Files\<DIR> Proxy Networks
[07/18/2008|11:48] C:\Program Files\<DIR> QuickTime
[04/11/2007|12:03] C:\Program Files\<DIR> Reference Assemblies
[05/01/2006|01:40] C:\Program Files\<DIR> RegEditX
[10/23/2007|03:11] C:\Program Files\<DIR> SensitivityToolkit
[04/24/2006|02:26] C:\Program Files\<DIR> SideCar
[04/30/2008|03:26] C:\Program Files\<DIR> Skype
[04/17/2007|07:38] C:\Program Files\<DIR> Sonic
[05/01/2006|05:00] C:\Program Files\<DIR> sprdprof
[01/17/2008|04:40] C:\Program Files\<DIR> SPSS
[11/09/2008|07:59] C:\Program Files\<DIR> Spybot - Search & Destroy
[04/24/2006|02:43] C:\Program Files\<DIR> SSH Communications Security
[06/01/2006|12:54] C:\Program Files\<DIR> StratX
[01/17/2008|01:17] C:\Program Files\<DIR> Symantec
[11/10/2008|09:12] C:\Program Files\<DIR> Symantec AntiVirus
[04/24/2006|10:03] C:\Program Files\<DIR> Symantec Client Security
[04/12/2006|02:17] C:\Program Files\<DIR> Synaptics
[04/17/2007|11:31] C:\Program Files\<DIR> SyncToy
[10/23/2007|11:37] C:\Program Files\<DIR> ThinkPad
[10/23/2007|12:27] C:\Program Files\<DIR> ThinkVantage
[10/23/2007|01:03] C:\Program Files\<DIR> ThinkVantage Fingerprint Software
[05/02/2006|11:07] C:\Program Files\<DIR> TreePlan
[11/09/2008|02:03] C:\Program Files\<DIR> Trend Micro
[08/09/2004|01:03] C:\Program Files\<DIR> Uninstall Information
[04/24/2006|11:11] C:\Program Files\<DIR> UPHClean
[10/23/2007|01:38] C:\Program Files\<DIR> VideoLAN
[04/30/2008|03:40] C:\Program Files\<DIR> Winamp
[10/23/2007|11:40] C:\Program Files\<DIR> Windows Desktop Search
[05/15/2007|10:27] C:\Program Files\<DIR> Windows Installer Clean Up
[04/24/2006|10:43] C:\Program Files\<DIR> Windows Media Connect
[01/11/2007|05:34] C:\Program Files\<DIR> Windows Media Connect 2
[09/20/2008|12:25] C:\Program Files\<DIR> Windows Media Player
[09/20/2008|12:25] C:\Program Files\<DIR> Windows NT
[08/09/2004|12:53] C:\Program Files\<DIR> WindowsUpdate
[11/08/2008|03:40] C:\Program Files\<DIR> WinZip
[08/09/2004|12:56] C:\Program Files\<DIR> xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[10/15/2008|08:35] C:\Program Files\Common Files\<DIR> Adobe
[05/04/2008|10:23] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[07/18/2008|11:44] C:\Program Files\Common Files\<DIR> Apple
[04/24/2006|02:12] C:\Program Files\Common Files\<DIR> Cisco Systems
[04/24/2006|12:30] C:\Program Files\Common Files\<DIR> DESIGNER
[10/23/2007|01:11] C:\Program Files\Common Files\<DIR> Deterministic Networks
[01/17/2008|04:07] C:\Program Files\Common Files\<DIR> Funk Software
[04/12/2006|02:33] C:\Program Files\Common Files\<DIR> InstallShield
[01/17/2008|08:49] C:\Program Files\Common Files\<DIR> InterVideo
[10/23/2007|01:19] C:\Program Files\Common Files\<DIR> Java
[04/24/2006|12:31] C:\Program Files\Common Files\<DIR> L&H
[02/06/2008|08:54] C:\Program Files\Common Files\<DIR> Lenovo
[01/17/2008|04:55] C:\Program Files\Common Files\<DIR> Macrovision Shared
[10/26/2008|10:59] C:\Program Files\Common Files\<DIR> Microsoft Shared
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> MSSoap
[01/17/2008|04:54] C:\Program Files\Common Files\<DIR> ODBC
[08/09/2004|12:53] C:\Program Files\Common Files\<DIR> Services
[04/30/2008|03:26] C:\Program Files\Common Files\<DIR> Skype
[10/08/2008|11:55] C:\Program Files\Common Files\<DIR> snpstd3
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> Sonic Shared
[08/09/2004|12:46] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/17/2007|07:38] C:\Program Files\Common Files\<DIR> SureThing Shared
[01/17/2008|01:17] C:\Program Files\Common Files\<DIR> Symantec Shared
[09/20/2008|12:24] C:\Program Files\Common Files\<DIR> System
[10/23/2007|01:01] C:\Program Files\Common Files\<DIR> ThinkVantage Fingerprint Software
[11/09/2008|01:28] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
--------------------\\ Process
( 85 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 10:06:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\CuteFtp\cuteftpcrack.zip
C:\DOCUME~1\AR~1.B\Desktop\Personnel\Software\FTP\Client\FTPExpert\Crack_Ftp_Client.zip
[F:1][D:2]-> C:\DOCUME~1\AR~1.B\LOCALS~1\Temp
[F:105][D:0]-> C:\DOCUME~1\AR~1.B\Cookies
[F:84][D:4]-> C:\DOCUME~1\AR~1.B\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled
1 - "C:\Lop SD\LopR_1.txt" - Mon 11/10/2008| 9:40 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Mon 11/10/2008|10:07 - Option : [2]
--------------------\\ Fin du rapport a 10:07:29
Et voici le rapport Hijackthis que j'ai lance apres ca:
Hijackthis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:15 AM, on 11/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Ok fais ce qui suit maintenant :
//!!\\ Le scan peut durer longtemps //!!\\
* Télécharge MalwareByte's Anti-Malware (by RubbeR DuckY) :
*http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
* Installe le programme sur le bureau :
S'il te manque "COMCTL32.OCX" lors de l'installation, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/
* Fais les mises à jour (clic sur Mises à jour puis Recherche de mises à jour)
* Démarre en mode sans échec
Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
Redémarres l’ordinateur
Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.
* Lance MalwareByte's Anti-Malware, clique sur Exécuter un examen complet puis Rechercher et sélectionnez tous tes disques durs
* // !! \\ Une fois le scan terminé, Si des elements on ete trouvés > cliques sur supprimer la selection. (si un message te demande de redémarrer le PC, accepte.)
* Un rapport sera généré, poste le ici.
@++
//!!\\ Le scan peut durer longtemps //!!\\
* Télécharge MalwareByte's Anti-Malware (by RubbeR DuckY) :
*http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebyte s anti malware
* Installe le programme sur le bureau :
S'il te manque "COMCTL32.OCX" lors de l'installation, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/
* Fais les mises à jour (clic sur Mises à jour puis Recherche de mises à jour)
* Démarre en mode sans échec
Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
Redémarres l’ordinateur
Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.
* Lance MalwareByte's Anti-Malware, clique sur Exécuter un examen complet puis Rechercher et sélectionnez tous tes disques durs
* // !! \\ Une fois le scan terminé, Si des elements on ete trouvés > cliques sur supprimer la selection. (si un message te demande de redémarrer le PC, accepte.)
* Un rapport sera généré, poste le ici.
@++
Salut E..T,
Desole pour la reponse tardive mais j'ai ete oblige de m'absenter.
J'ai lance le scan en mode sans echec, et il Malware a reussi a trouver des virus et a les supprimer. Yes!! :-)
Voici le log:
Malwarebytes' Anti-Malware 1.30
Database version: 1379
Windows 5.1.2600 Service Pack 3
11/10/2008 2:49:54 PM
mbam-log-2008-11-10 (14-49-54).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 153391
Time elapsed: 29 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678f7e1-c422-11d0-ad7d-00400515caaa} (Spyware.Comet.Cursor) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Downloaded Program Files\atmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
Ano
Desole pour la reponse tardive mais j'ai ete oblige de m'absenter.
J'ai lance le scan en mode sans echec, et il Malware a reussi a trouver des virus et a les supprimer. Yes!! :-)
Voici le log:
Malwarebytes' Anti-Malware 1.30
Database version: 1379
Windows 5.1.2600 Service Pack 3
11/10/2008 2:49:54 PM
mbam-log-2008-11-10 (14-49-54).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 153391
Time elapsed: 29 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678f7e1-c422-11d0-ad7d-00400515caaa} (Spyware.Comet.Cursor) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Downloaded Program Files\atmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
Ano
Voila le log de Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:08 PM, on 11/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:08 PM, on 11/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\taskswitch.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Donne moi des bonnes nouvelles ;)
Ca à l'air d'aller mieux non ??
Bon tu as des traces de norton sur ton PC, tu utilises norton ghost??
Si c'est pas le cas:
Utilise ça >> ftp://ftp.symantec.com/misc/consumer/RnisUPG.exe
Pour tout virer!
Vérifie JAVA >> ICI c'est une chose importante aussi.
Installe la dernière version de adobe >> Ici
Une foi que les nouvelles versions sont installées virent les anciennes par ajouts suppressions de programmes ou par le programme de désinstallation.
Pour l'antivirus vire avast correctement et installe AntiVir Personal Télécharges le ici puis installes ce dernier.
Je te mets un tutoriel complet sur son installation et son utilisation >> https://www.malekal.com/avira-free-security-antivirus-gratuit/
Une foi que tu as fait tout ça envoi un nouveau rapport hijack this.
++
Ca à l'air d'aller mieux non ??
Bon tu as des traces de norton sur ton PC, tu utilises norton ghost??
Si c'est pas le cas:
Utilise ça >> ftp://ftp.symantec.com/misc/consumer/RnisUPG.exe
Pour tout virer!
Vérifie JAVA >> ICI c'est une chose importante aussi.
Installe la dernière version de adobe >> Ici
Une foi que les nouvelles versions sont installées virent les anciennes par ajouts suppressions de programmes ou par le programme de désinstallation.
Pour l'antivirus vire avast correctement et installe AntiVir Personal Télécharges le ici puis installes ce dernier.
Je te mets un tutoriel complet sur son installation et son utilisation >> https://www.malekal.com/avira-free-security-antivirus-gratuit/
Une foi que tu as fait tout ça envoi un nouveau rapport hijack this.
++
Salut E..T,
J'ai suivi tes instructions et je viens de finir d'installer Avira. Par contre, j'essaie de mettre a jour les definitions des virus, mais je n'arrive pas a me connecter aux serveurs...
Lorsque je clique sur "Start update" dans Avira, j'obtiens un message "Checking file versions" puis Avira essaie de se connecter a un serveur. Il ne reussit pas a se connecter, alors il repart dans une boucle "Checking file versions" + tentative de connections a un nouveau serveur (different du precedent).
Les serveurs auxquels il tente de se connecte sont http://dl10.freeav.net, http://dl3.freeav.net, http://dl1.avgate.net, http://dl4.avgate.net, etc
A la fin, je vois qu'il arrive finalement a telecharger qqchose, mais apres j'obtiens un message "Status: internet connection failed". La fenetre specifique a l'update se ferme , et quand je reviens sur la fenetre principale, je vois qu'aucun update n'a ete effectue . (Last update: not performed).
As-tu deja vu ce type de comportement?
Merci,
Ano
J'ai suivi tes instructions et je viens de finir d'installer Avira. Par contre, j'essaie de mettre a jour les definitions des virus, mais je n'arrive pas a me connecter aux serveurs...
Lorsque je clique sur "Start update" dans Avira, j'obtiens un message "Checking file versions" puis Avira essaie de se connecter a un serveur. Il ne reussit pas a se connecter, alors il repart dans une boucle "Checking file versions" + tentative de connections a un nouveau serveur (different du precedent).
Les serveurs auxquels il tente de se connecte sont http://dl10.freeav.net, http://dl3.freeav.net, http://dl1.avgate.net, http://dl4.avgate.net, etc
A la fin, je vois qu'il arrive finalement a telecharger qqchose, mais apres j'obtiens un message "Status: internet connection failed". La fenetre specifique a l'update se ferme , et quand je reviens sur la fenetre principale, je vois qu'aucun update n'a ete effectue . (Last update: not performed).
As-tu deja vu ce type de comportement?
Merci,
Ano
Voici le log qui correspond a ce que je te disais dans mon message precedent:
10.11.2008 17:07:46 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
10.11.2008 17:07:46 - Backup Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
10.11.2008 17:07:46 - Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\
10.11.2008 17:07:46 - Using System's global Proxy settings
10.11.2008 17:07:46 - Launching GUI... display mode: 0
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
10.11.2008 17:07:46 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
10.11.2008 17:07:46 - Backup Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
10.11.2008 17:07:46 - Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\
10.11.2008 17:07:46 - Using System's global Proxy settings
10.11.2008 17:07:46 - Launching GUI... display mode: 0
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
10.11.2008 17:07:46 - Avira AntiVir Personal - Free Antivirus
10.11.2008 17:08:03 - Service unavailable
10.11.2008 17:08:03 - Switching to next update server
10.11.2008 17:08:21 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:08:21 - Master IDX file has changed
10.11.2008 17:08:36 - There was a problem updating from the specified server: Service unavailable
10.11.2008 17:08:36 - Switching to next update server
10.11.2008 17:08:52 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:08:52 - Master IDX file has changed
10.11.2008 17:09:07 - There was a problem updating from the specified server: Service unavailable
10.11.2008 17:09:07 - Switching to next update server
10.11.2008 17:09:23 - Service unavailable
10.11.2008 17:09:23 - Switching to next update server
10.11.2008 17:09:59 - Connection failed while downloading via the system proxy the file http://dl5.avgate.net/upd/idx/master.idx
10.11.2008 17:09:59 - Switching to next update server
10.11.2008 17:10:36 - Connection failed while downloading via the system proxy the file http://dl6.avgate.net/upd/idx/master.idx
10.11.2008 17:10:36 - Switching to next update server
10.11.2008 17:11:22 - Connection failed while downloading via the system proxy the file http://dl7.avgate.net/upd/idx/master.idx
10.11.2008 17:11:22 - Switching to next update server
10.11.2008 17:11:38 - Service unavailable
10.11.2008 17:11:38 - Switching to next update server
10.11.2008 17:11:59 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:11:59 - Master IDX file has changed
10.11.2008 17:12:35 - There was a problem updating from the specified server: Connection failed while downloading via the system proxy the file http://dl8.freeav.net/upd/idx/classic-nt-en.idx
10.11.2008 17:12:35 - Switching to next update server
10.11.2008 17:12:51 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:12:51 - Master IDX file has changed
10.11.2008 17:13:41 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress
10.11.2008 17:13:41 - Critical error: Service unavailable
Ano
10.11.2008 17:07:46 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
10.11.2008 17:07:46 - Backup Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
10.11.2008 17:07:46 - Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\
10.11.2008 17:07:46 - Using System's global Proxy settings
10.11.2008 17:07:46 - Launching GUI... display mode: 0
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
10.11.2008 17:07:46 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
10.11.2008 17:07:46 - Backup Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
10.11.2008 17:07:46 - Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\
10.11.2008 17:07:46 - Using System's global Proxy settings
10.11.2008 17:07:46 - Launching GUI... display mode: 0
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
10.11.2008 17:07:46 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
10.11.2008 17:07:46 - Avira AntiVir Personal - Free Antivirus
10.11.2008 17:08:03 - Service unavailable
10.11.2008 17:08:03 - Switching to next update server
10.11.2008 17:08:21 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:08:21 - Master IDX file has changed
10.11.2008 17:08:36 - There was a problem updating from the specified server: Service unavailable
10.11.2008 17:08:36 - Switching to next update server
10.11.2008 17:08:52 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:08:52 - Master IDX file has changed
10.11.2008 17:09:07 - There was a problem updating from the specified server: Service unavailable
10.11.2008 17:09:07 - Switching to next update server
10.11.2008 17:09:23 - Service unavailable
10.11.2008 17:09:23 - Switching to next update server
10.11.2008 17:09:59 - Connection failed while downloading via the system proxy the file http://dl5.avgate.net/upd/idx/master.idx
10.11.2008 17:09:59 - Switching to next update server
10.11.2008 17:10:36 - Connection failed while downloading via the system proxy the file http://dl6.avgate.net/upd/idx/master.idx
10.11.2008 17:10:36 - Switching to next update server
10.11.2008 17:11:22 - Connection failed while downloading via the system proxy the file http://dl7.avgate.net/upd/idx/master.idx
10.11.2008 17:11:22 - Switching to next update server
10.11.2008 17:11:38 - Service unavailable
10.11.2008 17:11:38 - Switching to next update server
10.11.2008 17:11:59 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:11:59 - Master IDX file has changed
10.11.2008 17:12:35 - There was a problem updating from the specified server: Connection failed while downloading via the system proxy the file http://dl8.freeav.net/upd/idx/classic-nt-en.idx
10.11.2008 17:12:35 - Switching to next update server
10.11.2008 17:12:51 - Copy file C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4918b0a3\idx/master.idx to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
10.11.2008 17:12:51 - Master IDX file has changed
10.11.2008 17:13:41 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress
10.11.2008 17:13:41 - Critical error: Service unavailable
Ano
Salut,
Chez mon père ça fait pareil;)
As tu réussi la?
Au cas ou >> http://www.commentcamarche.net/faq/sujet 8622 mise a jour d antivir impossible
@++
Chez mon père ça fait pareil;)
As tu réussi la?
Au cas ou >> http://www.commentcamarche.net/faq/sujet 8622 mise a jour d antivir impossible
@++
Salut E..T,
J'ai un peu galere pour faire l'update des definitions de virus, meme apres avoir modifie les registres comme tu me l'as indique. J'ai essaye plusieurs fois, et a chaque fois Antivir repartait dans le meme scenario que celui que je decrivais plus haut. Finalement, j'ai ete patient, je l'ai laisse faire jusau'au bout et ca l'a fait!!
Il m'a trouve 5 virus que j'ai effaces. Voici le log:
Log Antivir:
Avira AntiVir Personal
Report file date: Tuesday, November 11, 2008 01:41
Scanning for 1024586 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: 8-21612V
Version information:
BUILD.DAT : 8.2.0.336 16933 Bytes 10/30/2008 11:40:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 15:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 14:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 19:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 14:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 06:34:37
ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 11/9/2008 06:34:59
ANTIVIR2.VDF : 7.1.0.57 2048 Bytes 11/9/2008 06:35:14
ANTIVIR3.VDF : 7.1.0.65 52736 Bytes 11/10/2008 06:35:31
Engineversion : 8.2.0.29
AEVDF.DLL : 8.1.0.6 102772 Bytes 11/11/2008 06:39:40
AESCRIPT.DLL : 8.1.1.13 332156 Bytes 11/11/2008 06:39:08
AESCN.DLL : 8.1.1.5 123251 Bytes 11/11/2008 06:38:51
AERDL.DLL : 8.1.1.3 438645 Bytes 11/11/2008 06:38:34
AEPACK.DLL : 8.1.3.3 393591 Bytes 11/11/2008 06:38:15
AEOFFICE.DLL : 8.1.0.30 196986 Bytes 11/11/2008 06:37:56
AEHEUR.DLL : 8.1.0.71 1487222 Bytes 11/11/2008 06:37:39
AEHELP.DLL : 8.1.1.3 119157 Bytes 11/11/2008 06:37:13
AEGEN.DLL : 8.1.1.0 319859 Bytes 11/11/2008 06:36:57
AEEMU.DLL : 8.1.0.9 393588 Bytes 11/11/2008 06:36:38
AECORE.DLL : 8.1.4.1 172405 Bytes 11/11/2008 06:36:20
AEBB.DLL : 8.1.0.3 53618 Bytes 11/11/2008 06:36:03
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 15:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 16:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 11/11/2008 06:35:47
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 18:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 15:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 19:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 00:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 19:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 19:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 20:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 20:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: Tuesday, November 11, 2008 01:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'WINWORD.EXE' - '1' Module(s) have been scanned
Scan process 'OUTLOOK.EXE' - '1' Module(s) have been scanned
Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
Scan process 'Vtech Cordless Phone Suite.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'SideCar.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'vsnpstd3.exe' - '1' Module(s) have been scanned
Scan process 'tsnpstd3.exe' - '1' Module(s) have been scanned
Scan process 'FixCamera.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'hpztsb10.exe' - '1' Module(s) have been scanned
Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
Scan process 'acrotray.exe' - '1' Module(s) have been scanned
Scan process 'winampa.exe' - '1' Module(s) have been scanned
Scan process 'PhTray.exe' - '1' Module(s) have been scanned
Scan process 'VPTray.exe' - '1' Module(s) have been scanned
Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
Scan process 'ngtray.exe' - '1' Module(s) have been scanned
Scan process 'TpScrex.exe' - '1' Module(s) have been scanned
Scan process 'TPONSCR.exe' - '1' Module(s) have been scanned
Scan process 'TpShocks.exe' - '1' Module(s) have been scanned
Scan process 'TaskSwitch.exe' - '1' Module(s) have been scanned
Scan process 'UNavTray.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'TPOSDSVC.exe' - '1' Module(s) have been scanned
Scan process 'EZEJMNAP.EXE' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'SynTPLpr.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'SUService.exe' - '1' Module(s) have been scanned
Scan process 'uphclean.exe' - '1' Module(s) have been scanned
Scan process 'TpKmpSvc.exe' - '1' Module(s) have been scanned
Scan process 'TPHDEXLG.exe' - '1' Module(s) have been scanned
Scan process 'tvt_reg_monitor_svc.exe' - '1' Module(s) have been scanned
Scan process 'Rtvscan.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SavRoam.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'CTskMstr.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
Scan process 'DefWatch.exe' - '1' Module(s) have been scanned
Scan process 'cvpnd.exe' - '1' Module(s) have been scanned
Scan process 'btwdins.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ccSetMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'ibmpmsvc.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
79 processes with 79 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '100' files ).
Starting the file scan:
Begin scan in 'C:\' <Local Disk>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\34\30243be2-75e6b35e
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\cache\6.0\34\30243be2-75e6b35e
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\RECYCLER\S-1-5-21-1116490115-2857615688-2439805600-500\Dc1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP81\A0027818.exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/VB.flr back-door program
[NOTE] The file was deleted!
End of the scan: Tuesday, November 11, 2008 03:02
Used time: 1:20:44 Hour(s)
The scan has been done completely.
14021 Scanning directories
785191 Files were scanned
1 viruses and/or unwanted programs were found
5 Files were classified as suspicious:
6 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
785184 Files not concerned
10577 Archives were scanned
1 Warnings
6 Notes
Voici egalement le log Hijackthis que j'ai relance apres avoir deviruse l'ordi et l'avoir redemarre:
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:24:15 AM, on 11/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\AutoExNT.Exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
J'ai un peu galere pour faire l'update des definitions de virus, meme apres avoir modifie les registres comme tu me l'as indique. J'ai essaye plusieurs fois, et a chaque fois Antivir repartait dans le meme scenario que celui que je decrivais plus haut. Finalement, j'ai ete patient, je l'ai laisse faire jusau'au bout et ca l'a fait!!
Il m'a trouve 5 virus que j'ai effaces. Voici le log:
Log Antivir:
Avira AntiVir Personal
Report file date: Tuesday, November 11, 2008 01:41
Scanning for 1024586 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: 8-21612V
Version information:
BUILD.DAT : 8.2.0.336 16933 Bytes 10/30/2008 11:40:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 15:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 14:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 19:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 14:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 06:34:37
ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 11/9/2008 06:34:59
ANTIVIR2.VDF : 7.1.0.57 2048 Bytes 11/9/2008 06:35:14
ANTIVIR3.VDF : 7.1.0.65 52736 Bytes 11/10/2008 06:35:31
Engineversion : 8.2.0.29
AEVDF.DLL : 8.1.0.6 102772 Bytes 11/11/2008 06:39:40
AESCRIPT.DLL : 8.1.1.13 332156 Bytes 11/11/2008 06:39:08
AESCN.DLL : 8.1.1.5 123251 Bytes 11/11/2008 06:38:51
AERDL.DLL : 8.1.1.3 438645 Bytes 11/11/2008 06:38:34
AEPACK.DLL : 8.1.3.3 393591 Bytes 11/11/2008 06:38:15
AEOFFICE.DLL : 8.1.0.30 196986 Bytes 11/11/2008 06:37:56
AEHEUR.DLL : 8.1.0.71 1487222 Bytes 11/11/2008 06:37:39
AEHELP.DLL : 8.1.1.3 119157 Bytes 11/11/2008 06:37:13
AEGEN.DLL : 8.1.1.0 319859 Bytes 11/11/2008 06:36:57
AEEMU.DLL : 8.1.0.9 393588 Bytes 11/11/2008 06:36:38
AECORE.DLL : 8.1.4.1 172405 Bytes 11/11/2008 06:36:20
AEBB.DLL : 8.1.0.3 53618 Bytes 11/11/2008 06:36:03
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 15:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 16:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 11/11/2008 06:35:47
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 18:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 15:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 19:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 00:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 19:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 19:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 20:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 20:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: Tuesday, November 11, 2008 01:41
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'WINWORD.EXE' - '1' Module(s) have been scanned
Scan process 'OUTLOOK.EXE' - '1' Module(s) have been scanned
Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
Scan process 'Vtech Cordless Phone Suite.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'SideCar.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'vsnpstd3.exe' - '1' Module(s) have been scanned
Scan process 'tsnpstd3.exe' - '1' Module(s) have been scanned
Scan process 'FixCamera.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'hpztsb10.exe' - '1' Module(s) have been scanned
Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
Scan process 'acrotray.exe' - '1' Module(s) have been scanned
Scan process 'winampa.exe' - '1' Module(s) have been scanned
Scan process 'PhTray.exe' - '1' Module(s) have been scanned
Scan process 'VPTray.exe' - '1' Module(s) have been scanned
Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
Scan process 'ngtray.exe' - '1' Module(s) have been scanned
Scan process 'TpScrex.exe' - '1' Module(s) have been scanned
Scan process 'TPONSCR.exe' - '1' Module(s) have been scanned
Scan process 'TpShocks.exe' - '1' Module(s) have been scanned
Scan process 'TaskSwitch.exe' - '1' Module(s) have been scanned
Scan process 'UNavTray.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'TPOSDSVC.exe' - '1' Module(s) have been scanned
Scan process 'EZEJMNAP.EXE' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'SynTPLpr.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'SUService.exe' - '1' Module(s) have been scanned
Scan process 'uphclean.exe' - '1' Module(s) have been scanned
Scan process 'TpKmpSvc.exe' - '1' Module(s) have been scanned
Scan process 'TPHDEXLG.exe' - '1' Module(s) have been scanned
Scan process 'tvt_reg_monitor_svc.exe' - '1' Module(s) have been scanned
Scan process 'Rtvscan.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SavRoam.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'CTskMstr.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
Scan process 'DefWatch.exe' - '1' Module(s) have been scanned
Scan process 'cvpnd.exe' - '1' Module(s) have been scanned
Scan process 'btwdins.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ccSetMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'ibmpmsvc.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
79 processes with 79 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '100' files ).
Starting the file scan:
Begin scan in 'C:\' <Local Disk>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\34\30243be2-75e6b35e
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\cache\6.0\34\30243be2-75e6b35e
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\RECYCLER\S-1-5-21-1116490115-2857615688-2439805600-500\Dc1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\VFAgent.jar-7a70ac3c-632ddda4.zip
[0] Archive type: ZIP
--> com/videofurnace/player/VFAgentWin.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
[NOTE] The file was deleted!
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP81\A0027818.exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/VB.flr back-door program
[NOTE] The file was deleted!
End of the scan: Tuesday, November 11, 2008 03:02
Used time: 1:20:44 Hour(s)
The scan has been done completely.
14021 Scanning directories
785191 Files were scanned
1 viruses and/or unwanted programs were found
5 Files were classified as suspicious:
6 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
785184 Files not concerned
10577 Archives were scanned
1 Warnings
6 Notes
Voici egalement le log Hijackthis que j'ai relance apres avoir deviruse l'ordi et l'avoir redemarre:
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:24:15 AM, on 11/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\AutoExNT.Exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
C'est possible. C'etait installe de base sur l'ordi. Si c'est le cas (et j'imagine que c'est le cas), est-il possible de la desactiver sans le desinstaller?
Mon souci, c'est que c'est un portable que j'ai du acheter pendant mes etudes a l'etranger, et qu'ils ne nous ont rien donne pour reinstaller "from scratch" en cas de souci. Je prefere donc eviter de desinstaller ce qui fait partie de la configuration de base.
Ano
Ano
Tu as quoi comme pare feu?
Tu vas fixer cette ligne avec hijackthis c'est pur norton ghost,
Comme suit
Tu réouvres hijack
Tu refais un scan en choisissant >> Do a system scan and loge and file
Et après tu verras une option Fix checked coche la ligne et valides.
//!!\\Seulement celle la//!!\\
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
Par contre il y a des traces de l'antivirus virent les avec ce soft >> ftp://ftp.symantec.com/misc/consumer/RnisUPG.exe
Et ce n'est pas bon si il y a des traces de norton, ton antivirus n'est pas fiable à 100% après tu fais comme tu veux!
Une foi que tu as fais tout ça et si tu veux arrêter la :
Télécharge ToolsCleaner il permet de supprimer les logiciels installés pendant la désinfection.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
@+
Tu vas fixer cette ligne avec hijackthis c'est pur norton ghost,
Comme suit
Tu réouvres hijack
Tu refais un scan en choisissant >> Do a system scan and loge and file
Et après tu verras une option Fix checked coche la ligne et valides.
//!!\\Seulement celle la//!!\\
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
Par contre il y a des traces de l'antivirus virent les avec ce soft >> ftp://ftp.symantec.com/misc/consumer/RnisUPG.exe
Et ce n'est pas bon si il y a des traces de norton, ton antivirus n'est pas fiable à 100% après tu fais comme tu veux!
Une foi que tu as fais tout ça et si tu veux arrêter la :
Télécharge ToolsCleaner il permet de supprimer les logiciels installés pendant la désinfection.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
@+
J'avais deja lance RnisUPG.exe precedemment. Je l'ai relance a nouveau en virant ngtray.exe au prealable.
Par je n'ai pas encore lance toolscleaner au cas ou ca ne sera pas encore bon.
Voici les log:
Log RnisUPG
PRODUCT(S)
Norton Internet Security 2000 1.0
Norton Personal Firewall 2000 2.0
Norton Internet Security 2000 2.0
Norton Internet Security Family Edition 2000 2.0
Norton Personal Firewall 2001 2.5
Norton Internet Security 2001 2.5
Norton Internet Security Family Edition 2001 2.5
Norton Personal Firewall 2001 3.0
Norton Internet Security 2001 3.0
Norton Internet Security Family Edition 2001 3.0
Norton Personal Firewall 2002 4.0
Norton Internet Security 2002 4.0
Norton Internet Security Professional 2002 4.5
Norton Personal Firewall 2003 6.0
Norton Internet Security 2003 6.0
Norton Internet Security Professional 2003 6.0
INSTALLED DIRECTORY
ACTIVE SERVICES/PROCESSES
Stopping SymPxSvc
Stopping NISSERV
Stopping NISUM
Stopping ccEvtMgr
Stopping ccPwdSvc
Stopping ccPxySvc
WINDOWS INSTALLER INFORMATION
Remove Windows Installer Information for Norton Internet Security 1.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E16453A0-3AED-11D3-AF47-00600811C705}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C26B870B-08E6-442A-AAE3-6A250CCFE94E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7C1A7F8E-3662-4B0C-A573-C680C043E80E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ED4D92D3-7DE4-49AF-8B1C-CA1B7B9274D2}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF8FE655-CAD3-4E71-AC80-140A7F842CB3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C02388E1-C0E3-462E-BDC8-7E1D56D8AC4D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9209615F-276E-4406-8607-DF2B3C9F0F34}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCAE58EF-511C-44D7-81F2-D32876A04EEA}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0AE91EA0-83D4-49B9-ADF7-B769F7D091A4}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D17CC1F3-FC25-41B6-9F9F-68295B4E177B}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D54BDAC-C362-4849-B52F-814319CF5057}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 4.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{72AAF846-3C35-4391-9459-CC7B6EC7E07A}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15BFECE8-A100-4861-B92B-1EFF76683C23}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{93DF5BBA-2992-482F-B11D-91027EC8AC7D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Total references deleted = 0
LIVEUPDATE
Unregister {8BBAA23E-A16C-4899-B3BD-CA5FE6A07011} with LiveUpdate
Unregister {A0B7DE31-6FB5-4e1f-8F82-F1E5E9F968EB} with LiveUpdate
Unregister {BAAFC3EB-C2A9-4572-983A-54D1FFC75B18} with LiveUpdate
Unregister {C0DA9CA0-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA1-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA2-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA3-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {2A4E728E-ECD1-4ec8-A451-2D719C7EEF10} with LiveUpdate
Unregister {5911B56B-54AA-4678-9933-9413CB93B23C} with LiveUpdate
Unregister {6E34DCC1-B194-11d2-A11E-00409500AD7D} with LiveUpdate
Unregister {DC4CC242-AB75-4bfe-A51E-4CE500ADD552} with LiveUpdate
Unregister {94014D45-7F26-48ca-9CE5-79E39A01A6A6} with LiveUpdate
LIVESUBSCRIBE
Unregister B211DA60-6B70-11d3-9775-005004D12CC3 with LiveSubscribe
SERVICE DEPENDENCIES
Removing SymEvent IDs
SymEvent ID not found: SymNetDrv
SERVICES
REGISTRY KEYS
Delete Software\Symantec\IAM
Delete Software\Symantec\IAM.tmp
Delete Software\Symantec\IAM.old
Delete Software\Symantec\SymReg
Delete Software\Symantec\ccReg
Delete Software\Symantec\CommonClient
COM SERVERS AND FILE EXTENSIONS
SHORTCUTS
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security Professional.lnk
FILES AND DIRECTORIES
File doesn't exist: C:\WINDOWS\system32\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDSCo.sys
File doesn't exist: C:\WINDOWS\system32\sr.dat
File doesn't exist: C:\DOCUME~1\AR~1.B\LOCALS~1\Temp\deleteme.bat
File doesn't exist: C:\WINDOWS\temp\deleteme.bat
File doesn't exist: C:\WINDOWS\system32\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.INF
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.CAT
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDRV.SYS
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\drivers\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\sr2.dat
File doesn't exist: C:\WINDOWS\system32\SymNeti.dll
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SymTdiRg.exe
File doesn't exist: %SYMC_SRD%\Default.rul
File doesn't exist: %SYMC_SRD%\Persist.dat
File doesn't exist: C:\WINDOWS\system32\ccTrust.dll
File doesn't exist: C:\WINDOWS\system32\ccPasswd.dll
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:49 PM, on 11/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Par je n'ai pas encore lance toolscleaner au cas ou ca ne sera pas encore bon.
Voici les log:
Log RnisUPG
PRODUCT(S)
Norton Internet Security 2000 1.0
Norton Personal Firewall 2000 2.0
Norton Internet Security 2000 2.0
Norton Internet Security Family Edition 2000 2.0
Norton Personal Firewall 2001 2.5
Norton Internet Security 2001 2.5
Norton Internet Security Family Edition 2001 2.5
Norton Personal Firewall 2001 3.0
Norton Internet Security 2001 3.0
Norton Internet Security Family Edition 2001 3.0
Norton Personal Firewall 2002 4.0
Norton Internet Security 2002 4.0
Norton Internet Security Professional 2002 4.5
Norton Personal Firewall 2003 6.0
Norton Internet Security 2003 6.0
Norton Internet Security Professional 2003 6.0
INSTALLED DIRECTORY
ACTIVE SERVICES/PROCESSES
Stopping SymPxSvc
Stopping NISSERV
Stopping NISUM
Stopping ccEvtMgr
Stopping ccPwdSvc
Stopping ccPxySvc
WINDOWS INSTALLER INFORMATION
Remove Windows Installer Information for Norton Internet Security 1.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E16453A0-3AED-11D3-AF47-00600811C705}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Microsoft\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Products\0A35461EDEA33D11FA74000680117C50
Delete HKLM\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Delete HKCU\Software\Classes\Installer\Features\0A35461EDEA33D11FA74000680117C50
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C26B870B-08E6-442A-AAE3-6A250CCFE94E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Microsoft\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Products\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKLM\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Delete HKCU\Software\Classes\Installer\Features\B078B62C6E80A244AA3EA652C0FC9EE4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7C1A7F8E-3662-4B0C-A573-C680C043E80E}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Microsoft\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Products\E8F7A1C72663C0B45A376C080C348EE0
Delete HKLM\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Delete HKCU\Software\Classes\Installer\Features\E8F7A1C72663C0B45A376C080C348EE0
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ED4D92D3-7DE4-49AF-8B1C-CA1B7B9274D2}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Microsoft\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Products\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKLM\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Delete HKCU\Software\Classes\Installer\Features\3D29D4DE4ED7FA94B8C1ACB1B729472D
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF8FE655-CAD3-4E71-AC80-140A7F842CB3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Microsoft\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Products\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKLM\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Delete HKCU\Software\Classes\Installer\Features\556EF8FF3DAC17E4CA0841A0F748C23B
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C02388E1-C0E3-462E-BDC8-7E1D56D8AC4D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Microsoft\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Products\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKLM\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Delete HKCU\Software\Classes\Installer\Features\1E88320C3E0CE264DB8CE7D1658DCAD4
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 2.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9209615F-276E-4406-8607-DF2B3C9F0F34}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Microsoft\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Products\F5169029E67260446870FDB2C3F9F043
Delete HKLM\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Delete HKCU\Software\Classes\Installer\Features\F5169029E67260446870FDB2C3F9F043
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCAE58EF-511C-44D7-81F2-D32876A04EEA}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Microsoft\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Products\FE85EACCC1157D44182F3D82670AE4AE
Delete HKLM\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Delete HKCU\Software\Classes\Installer\Features\FE85EACCC1157D44182F3D82670AE4AE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0AE91EA0-83D4-49B9-ADF7-B769F7D091A4}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Microsoft\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Products\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKLM\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Delete HKCU\Software\Classes\Installer\Features\0AE19EA04D389B94DA7F7B967F0D194A
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Family Edition 3.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D17CC1F3-FC25-41B6-9F9F-68295B4E177B}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Microsoft\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Products\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKLM\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Delete HKCU\Software\Classes\Installer\Features\3F1CC71D52CF6B14F9F98692B5E471B7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D54BDAC-C362-4849-B52F-814319CF5057}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Microsoft\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Products\CADB45D1263C94845BF2183491FC0575
Delete HKLM\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Delete HKCU\Software\Classes\Installer\Features\CADB45D1263C94845BF2183491FC0575
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 4.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{71D03DD3-C6D9-4503-A1CC-FBA576F6CFE3}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Microsoft\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Products\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKLM\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Delete HKCU\Software\Classes\Installer\Features\3DD30D179D6C30541ACCBF5A676FFC3E
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 4.5
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{72AAF846-3C35-4391-9459-CC7B6EC7E07A}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Microsoft\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Products\648FAA2753C319344995CCB7E67C0EA7
Delete HKLM\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Delete HKCU\Software\Classes\Installer\Features\648FAA2753C319344995CCB7E67C0EA7
Total references deleted = 0
Remove Windows Installer Information for Norton Personal Firewall 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15BFECE8-A100-4861-B92B-1EFF76683C23}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Microsoft\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Products\8ECEFB51001A16849BB2E1FF6786C332
Delete HKLM\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Delete HKCU\Software\Classes\Installer\Features\8ECEFB51001A16849BB2E1FF6786C332
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AFD2C5B5-BF78-47B6-9569-755448C0D0EE}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Microsoft\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Products\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKLM\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Delete HKCU\Software\Classes\Installer\Features\5B5C2DFA87FB6B7459965745840C0DEE
Total references deleted = 0
Remove Windows Installer Information for Norton Internet Security Professional 6.0
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\LocalPackages\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{93DF5BBA-2992-482F-B11D-91027EC8AC7D}
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Microsoft\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Products\ABB5FD392992F2841BD11920E78CCAD7
Delete HKLM\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Delete HKCU\Software\Classes\Installer\Features\ABB5FD392992F2841BD11920E78CCAD7
Total references deleted = 0
LIVEUPDATE
Unregister {8BBAA23E-A16C-4899-B3BD-CA5FE6A07011} with LiveUpdate
Unregister {A0B7DE31-6FB5-4e1f-8F82-F1E5E9F968EB} with LiveUpdate
Unregister {BAAFC3EB-C2A9-4572-983A-54D1FFC75B18} with LiveUpdate
Unregister {C0DA9CA0-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA1-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA2-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {C0DA9CA3-758C-11d3-9778-005004D12CC3} with LiveUpdate
Unregister {2A4E728E-ECD1-4ec8-A451-2D719C7EEF10} with LiveUpdate
Unregister {5911B56B-54AA-4678-9933-9413CB93B23C} with LiveUpdate
Unregister {6E34DCC1-B194-11d2-A11E-00409500AD7D} with LiveUpdate
Unregister {DC4CC242-AB75-4bfe-A51E-4CE500ADD552} with LiveUpdate
Unregister {94014D45-7F26-48ca-9CE5-79E39A01A6A6} with LiveUpdate
LIVESUBSCRIBE
Unregister B211DA60-6B70-11d3-9775-005004D12CC3 with LiveSubscribe
SERVICE DEPENDENCIES
Removing SymEvent IDs
SymEvent ID not found: SymNetDrv
SERVICES
REGISTRY KEYS
Delete Software\Symantec\IAM
Delete Software\Symantec\IAM.tmp
Delete Software\Symantec\IAM.old
Delete Software\Symantec\SymReg
Delete Software\Symantec\ccReg
Delete Software\Symantec\CommonClient
COM SERVERS AND FILE EXTENSIONS
SHORTCUTS
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Personal Firewall.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security Family Edition.lnk
File doesn't exist: C:\Documents and Settings\All Users\Desktop\Norton Internet Security Professional.lnk
File doesn't exist: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton Internet Security Professional.lnk
FILES AND DIRECTORIES
File doesn't exist: C:\WINDOWS\system32\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\NDISFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\FWFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\DNSFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\HTTPFILT.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDSCo.sys
File doesn't exist: C:\WINDOWS\system32\sr.dat
File doesn't exist: C:\DOCUME~1\AR~1.B\LOCALS~1\Temp\deleteme.bat
File doesn't exist: C:\WINDOWS\temp\deleteme.bat
File doesn't exist: C:\WINDOWS\system32\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMDNS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMFW.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SymIDS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMNDIS.sys
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.INF
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.CAT
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDRV.SYS
File doesn't exist: C:\WINDOWS\system32\drivers\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\drivers\SYMTDI.sys
File doesn't exist: C:\WINDOWS\system32\sr2.dat
File doesn't exist: C:\WINDOWS\system32\SymNeti.dll
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SYMREDIR.DLL
File doesn't exist: C:\WINDOWS\system32\SymTdiRg.exe
File doesn't exist: %SYMC_SRD%\Default.rul
File doesn't exist: %SYMC_SRD%\Persist.dat
File doesn't exist: C:\WINDOWS\system32\ccTrust.dll
File doesn't exist: C:\WINDOWS\system32\ccPasswd.dll
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
File doesn't exist: CommonClient
Log Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:49 PM, on 11/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Proxy Networks\Proxy Host\phtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SideCar\SideCar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Find as you type Helper - {186A2813-D175-4cf8-B179-3873AC4E975C} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Find as you type - {4AE165F6-CCA4-4e9a-98CE-C2FE8B59F383} - C:\Program Files\Ookii.org Find As You Type 1.3\InternetExplorerISearch.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Proxy Networks\Proxy Host\phtray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [supportdir] cmd /c "rmdir /q /s "C:\WINDOWS\TEMP\{48227AEB-DC8E-4A90-A274-0B4A39D699B1}"" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [configmsi] cmd /c "rmdir /q C:\config.msi" (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: SideCar DCIS Authentication.lnk = C:\Program Files\SideCar\SideCar.exe
O4 - Global Startup: usb7100 Startup.lnk = C:\Program Files\Cordless USB Phone\Vtech Cordless Phone Suite.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8B84E36B-7DEE-11D2-A457-0060976E5CAC} (ShowCal Control) - https://tucknt5x.dartmouth.edu/agx-bd/agenda/showcal.ocx
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://7city-learning1.webex.com/client/T26L/webex/ieatgpc.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ERU Autobackup (AutoExNT) - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\Pharos\Bin\CTskMstr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe