J'y comprends rien!

Résolu
Bonjour,
alors que je n'ai rien fait d'anormal, certaines icones sur le bureau de mon ordi ont changé(sauf mes docs, le poste de travail, mes programmes et la corbeille). les fenetres de mes menus ne s'affichent plus de la meme maniere(il manque le menu a gauche) et je ne peux plus eteindre mon ordi a partir du menu démarrer.j'ai fait plusieurs analyses:avast, norton scan,spybot,spyware doctor et ils n'ont trouvé que des risque faible que j'ai pu éliminer,ils n'ont pas trouvé de gros risque. malgrè ces analyses mon problème reste le meme,rien a changé.
Configuration: Windows XP
Internet Explorer 6.0

43 réponses

Résumé de la discussion

Des icônes du bureau ont changé sans raison apparente, les fenêtres des menus s'affichent différemment avec le menu gauche manquant et l'arrêt via le menu démarrer est inopérant sur Windows XP avec IE6. Plusieurs participants suggèrent d'examiner les éléments de démarrage et les extensions via des outils comme HijackThis, d'effectuer des analyses antivirus complémentaires et, si nécessaire, de redémarrer en mode sans échec pour restaurer les fonctions système. Des éléments relevés dans les rapports, notamment de nombreuses entrées de démarrage et des services tiers, soulignent la nécessité d'une vérification approfondie et d'une sauvegarde complète des données avant toute modification du système.

Bobot (l’IA à votre service)
  1. slt
    j'ai des pbs similaires sur mon ordi
    ce n'est pas un virus
    avez vous fait une mise à jour de windows recemment??
    pour ma part oui
    je crois que l'on peut dire merci à la société microsoft et ses logiciels de m....
    1. salut !!
      c'est nOrmale !!
      t'a peut etre supp des fichier system !!!
      alOrs il faut que tu les recuP !!
      ou bien que tu fOrmate tOn PC !!
      1. ok. je suis pas trop une pro de l'ordi, alors pourrais tu me dire comment faire pour recuperer des fichiers systeme ou pr formater mon ordi
        1. salut tu pourrais me dire comment recuperer des fichiers system ou formater mon ordi? car je trouve pas, je sais pas bien où aller.
          1. non j'en ai pas. et sinon pour recup des fichiers je vais où? et comment je peux savoir lesquels st a recuperer?
            1. bonjour avant de faire n'importe quoi , poste moi un rapport de ton systeme avec hijackthis

              Télécharge sur le bureau " hijackthis "
              ftp://ftp.commentcamarche.com/download/HJTInstall.exe
              = Clic-droit sur Hijackthis
              = Extraire ici ( ou extraire sans confirmation ou tout ou unzip)
              = clic droit sur Hijackthis ==> renommer ==> écrire : test.exe ( à la place de hijackthis.exe) <== Important
              =Double-clic dessus
              = Clic Do a system scan and save the log
              =coller le rapport
              si problème voir l'aide
              http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
              1. salut merci de ta reponse voila le rapport!
            2. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:52:16, on 05/02/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              C:\WINDOWS\ehome\ehtray.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
              C:\apps\ABoard\ABoard.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\apps\ABoard\AOSD.exe
              C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Real\RealPlayer\RealPlay.exe
              C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\APPS\SMP\SmpSys.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\eHome\ehmsas.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
              O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
              O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
              O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
              O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
              O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
              O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?48e9404bb6fe4e3d83a39f6da8125f34
              O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?48e9404bb6fe4e3d83a39f6da8125f34
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

              --
              1. télécharges smitfraudfix :

                En image :
                http://siri.urz.free.fr/Fix/SmitfraudFix.php

                tu doubles cliques sur smitfraudfix.cmd et tu choisi l option 1
                cela vas générer un rapport.

                Copie/colle le rapport sur le forum stp.

                1. OUI c Ossi 1e methOde pratique !!
                  mAis Sii ta 1 CD windOws alOrs :

                  1) Démarre à partir de la Console de récupération.
                  2) Saisisse ces commandes :
                  fixboot
                  chkdsk c: /p /r
                  Modifie éventuellement la lettre de lecteur puis redémarrez...
                  3) Si cela ne suffit pas, reviens dans la console de récupération et places toi à la racine de votre lecteur puis tape :
                  cd ..
                  4) Saisisse la lettre de ton lecteur de CD-ROM, par exemple : D:
                  5) Afin de te placer dans ce répertoire, saisisse : cd i386
                  6) Tape les commandes suivantes qui vont te permettent de transférer les fichiers systèmes :
                  copy ntldr c: (valide à chaque ligne)
                  copy Ntdetect.com
                  fixboot
                  exit

                  C'est tout !!!
                  1. SmitFraudFix v2.281

                    Rapport fait à 15:40:22,71, 05/02/2008
                    Executé à partir de C:\Documents and Settings\Lauren Kayser\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\system32\RUNDLL32.EXE
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                    C:\apps\ABoard\ABoard.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\apps\ABoard\AOSD.exe
                    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Real\RealPlayer\RealPlay.exe
                    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                    C:\WINDOWS\ehome\mcrdsvc.exe
                    C:\APPS\SMP\SmpSys.exe
                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\eHome\ehmsas.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lauren Kayser

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lauren Kayser\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\LAUREN~1\Favoris

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    IEDFix.exe by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: VIA Rhine II Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 192.168.1.1

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    1. Smitfraud option 2

                      Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5).
                      ----------------------------------------------------------------------------
                      Relance le programme Smitfraud,
                      Cette fois choisit l’option 2, répond oui a tous ;
                      Sauvegarde le rapport, Redémarre en mode normal,
                      copie/colle le rapport sauvegardé sur le forum
                      1. le problème c'est que je peux pas eteindre l'ordi a partir du menu demarrer, que dois je faire?
                    2. redemarre , bouton d'arret .
                      1. salut, j'ai redémarrer mon ordi en mode sans échec et tout remarche par contre je peux pas t'envoyer le deuxieme rapport de smitfraudfix car la fenetre qui s'ouvre n'est plus la meme et je ne sais pas où aller. quand je clique sur les icones du menu de smitfraudfix les fenetre ne s'ouvrent pas..??
                    3. poste moi par la meme un nouveau rapport hijackthis
                      1. salut, voilà la copie du rapport SmitFraudFix v2.281

                        Rapport fait à 15:40:22,71, 05/02/2008
                        Executé à partir de C:\Documents and Settings\Lauren Kayser\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\system32\RUNDLL32.EXE
                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                        C:\apps\ABoard\ABoard.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\apps\ABoard\AOSD.exe
                        C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Real\RealPlayer\RealPlay.exe
                        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                        C:\WINDOWS\ehome\mcrdsvc.exe
                        C:\APPS\SMP\SmpSys.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\Program Files\Windows Live\Messenger\usnsvc.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\WINDOWS\system32\NOTEPAD.EXE
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lauren Kayser

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lauren Kayser\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\LAUREN~1\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                        "Source"="About:Home"
                        "SubscribedURL"="About:Home"
                        "FriendlyName"="Ma page d'accueil"

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        IEDFix.exe by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "System"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        Description: VIA Rhine II Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
                        DNS Server Search Order: 192.168.1.1

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin
                      2. et voici unnouveau Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 22:56:47, on 06/02/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\RUNDLL32.EXE
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                        C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                        C:\apps\ABoard\ABoard.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\apps\ABoard\AOSD.exe
                        C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Real\RealPlayer\RealPlay.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\APPS\SMP\SmpSys.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\Program Files\Windows Live\Messenger\usnsvc.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Windows Live Toolbar\msn_sl.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                        O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
                        O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                        O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
                        O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
                        O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
                        O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?48e9404bb6fe4e3d83a39f6da8125f34
                        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?48e9404bb6fe4e3d83a39f6da8125f34
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                        O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                        O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                    4. bonsoir tu l'as execute en mode normal il faut le faire en mode sans echec Fix executé en mode normal
                      1. petit nettoyage avant de commencer .

                        1) telecharge avg anti spyware et ccleaner

                        Telecharge AVG anti spywares

                        http://www.grisoft.com/doc/downloads-products/ww/crp/0?prd=triasw
                        Installe le puis...Lancer AVG Anti-Spyware.
                        Clique sur le menu Mise à jour.
                        Dans le paragraphe Mise à jour manuelle, cliquer sur le bouton Commencer la mise à jour.
                        Attends la fin de cette mise à jour puis ferme le programme.
                        Ne pas lancer d'analyse maintenant

                        Telecharge

                        -- CCleaner
                        https://www.ccleaner.com/ccleaner/download
                        Choisi de préférence la version SLIM-No Toolbar.
                        Installe-le en prenant soin de décocher les diverses options dont la barre Yahoo et la mise à jour.
                        Lance CCleaner puis Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
                        Pour les autres paramètres, laisse-le avec ses réglages par défaut.
                        Ferme le programme pour l’instant.

                        2) Redémarre en mode sans échec

                        Regarde ici avant : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm
                        Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
                        Sélectionner "Mode sans échec" et appuie sur [Entrée]
                        Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.

                        Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

                        3) Lance AVG Anti-Spyware 7.5

                        --Réglages

                        Clique sur le menu Analyse (de la barre d'outils).
                        Clique sur l'onglet Paramètres.
                        Dans Comment réagir? clique sur Actions recommandées et choisir Quarantaine.
                        Dans Comment faire l'analyse ? et dans Programmes potentiellement dangereux, vérifier que toutes les cases soient cochées.
                        Dans Rapports cocher "générer un rapport après chaque analyse"

                        -- Scan
                        Dans l'onglet Analyse
                        Clique sur Analyse complète du système.
                        Important : Ne pas ouvrir de fenêtre, ne pas lancer de programme pendant l'exécution de AVG Anti-Spyware, car cela pourrait interférer avec le processus de recherche.
                        Cliquer sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.(C:\Programfiles\AVG Antispyware 7.5\Reports)
                        Ensuite
                        Très important : A la fin de l'analyse, clique sur " Appliquer toutes les actions"

                        Puis ferme AVG Anti-Spyware.

                        4) Suppression de fichiers inutiles avec CCleaner

                        Lance CCleaner en double-cliquant sur son raccourci sur le bureau.
                        Puis dans le menu Nettoyeur
                        Clique sur Analyse (laisser travailler cela peut durer longtemps la 1ere fois)
                        Clique sur le bouton Lancer le nettoyage.
                        Clique une seconde fois sur le bouton Lancer le nettoyage
                        clique sur registre cherche et repare les erreurs effectue trois fois la manipe pour que se sois efficace !

                        5) Rapports

                        Fais redémarrer le PC en mode normal puis poste en réponse :

                        * Le rapport d AVG antispyware 7.5 situé ici C:\Programfiles\AVG Antispyware 7.5\Reports
                        1. salut merci de m'avoir tout expliqué en détails ça a été plus facile pr moi; voici le rapport AVG:

                          ---------------------------------------------------------
                          AVG Anti-Spyware - Rapport d'analyse
                          ---------------------------------------------------------

                          + Créé à: 19:06:45 05/12/2007

                          + Résultat de l'analyse:

                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@247realmedia[2].txt -> TrackingCookie.247realmedia : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@maisondevalerie.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@redcats.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@adrevolver[2].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@adtech[2].txt -> TrackingCookie.Adtech : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@adviva[1].txt -> TrackingCookie.Adviva : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@casinotropez[1].txt -> TrackingCookie.Casinotropez : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@www.casinotropez[1].txt -> TrackingCookie.Casinotropez : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@stat.dealtime[1].txt -> TrackingCookie.Dealtime : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@fastclick[2].txt -> TrackingCookie.Fastclick : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ehg-cogemag.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ehg-neuftelecom.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@mediaplex[2].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@overture[2].txt -> TrackingCookie.Overture : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@questionmarket[1].txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@h.starware[1].txt -> TrackingCookie.Starware : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@try.starware[2].txt -> TrackingCookie.Starware : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@statcounter[2].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@vegasred[1].txt -> TrackingCookie.Vegasred : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@www.vegasred[1].txt -> TrackingCookie.Vegasred : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
                          C:\Documents and Settings\Lauren Kayser\Cookies\lauren kayser@zedo[2].txt -> TrackingCookie.Zedo : Aucune action entreprise.

                          Fin du rapport
                        2. en fait je n'ai pas de dossier "reports" a l'emplacement indiqué dc je t'ai posté un rapport qui récapitule tout les problèmes observés lors de l'analyse en mode ss echec. AVG a trouvé 21 infections "trackingcookie"et j'ai cliqué sur "appliquer ttes les actions" et ça les a supprimés
                      2. ok tu as bien nettoyer et reparer eles erreurs avec ccleaner ?

                        Scan online avec BitDefender
                        Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
                        Une fois qu'il a terminé colle le rapport ici stp
                        https://www.bitdefender.com/toolbox/
                        Copie/Colle le rapport
                        http://www.malekal.com/tutorial_BitDefender_AntiSpyware.php
                        https://kerio.probb.fr/
                        http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                        1. en fait j'ai recommencé l'analyse avec AVG en mode sans echec et il a trouvé encore 5 menaces:
                          TrackingCookie.Advertising
                          TrackingCookie.Atdmt
                          TrackingCookie.Bluestreak
                          TrackingCookie.Doubleclick
                          TrackingCookie.Netflame
                          le risque etait moyen et je les ai supprimés.
                          j'ai nettoyé et reparer les erreurs avec ccleaner.

                          voici le rapportde smitfraud 2:

                          SmitFraudFix v2.281

                          Rapport fait à 23:13:48,71, 07/02/2008
                          Executé à partir de C:\Documents and Settings\Lauren Kayser\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode sans echec

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix.exe by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{2746C2DB-EDF6-4527-87F5-F1D442671345}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                          Nettoyage terminé.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin

                          par contre au redémarrage de l'ordi, spybot me demande plusieurs fois si j'autorise des modifications importante du registre. dois-je accepter?
                        2. voici le rapport BitDefender:

                          [General]
                          App = "BitDefender Online Scanner v8"
                          Date = 08:02:2008
                          Time = 01:07:21
                          Scan Path = C:\;D:\;E:\;F:\;G:\;H:\;

                          [Engines Info]
                          Virus Definitions = 979738
                          Engine build = "AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)"
                          Scan plugins = 16
                          Archive plugins = 41
                          Unpack plugins = 7
                          E-mail plugins = 6
                          System plugins = 5

                          [Scan Statistics]
                          Folders = 7174
                          Files = 271713
                          Archives = 7296
                          Packed files = 14198
                          Identified viruses = 4
                          Infected files = 8
                          Warnings = 0
                          Suspect files = 0
                          Disinfected files = 0
                          Deleted files = 8
                          Copied files = 0
                          Moved files = 0
                          Renamed files = 0
                          I/O Errors = 35

                          [Scan Settings]
                          SecondAction = Delete
                          FirstAction = Disinfect
                          Heuristics = 1
                          Enable Warnings = 1
                          Exclude Ext =
                          Extensions = *;
                          Scan Emails = 1
                          Scan Archives = 1
                          Scan Packed = 1
                          Scan Files = 1
                          Scan Boot = 1
                          Verify Memory = 0

                          [Scan Results]
                          Line00000022 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024525.exe Detected with: Adware.MSNSkinner.A"
                          Line00000021 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024525.exe Deleted"
                          Line00000020 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024526.dll Detected with: Adware.MSNSkinner.A"
                          Line00000019 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024526.dll Deleted"
                          Line00000018 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024531.exe=>(NSIS o)=>lzma_solid_nsis0005 Detected with: Adware.NaviPromo.BYC"
                          Line00000017 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024531.exe=>(NSIS o)=>lzma_solid_nsis0005 Disinfection failed"
                          Line00000016 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024531.exe=>(NSIS o)=>lzma_solid_nsis0005 Deleted"
                          Line00000015 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP134\A0024531.exe=>(NSIS o) Update failed"
                          Line00000014 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031287.exe Detected with: Adware.Navipromo.BZC"
                          Line00000013 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031287.exe Disinfection failed"
                          Line00000012 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031287.exe Deleted"
                          Line00000011 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031288.exe Detected with: Adware.Navipromo.BZC"
                          Line00000010 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031288.exe Disinfection failed"
                          Line00000009 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031288.exe Deleted"
                          Line00000008 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031289.exe Detected with: Adware.Navipromo.BYT"
                          Line00000007 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031289.exe Disinfection failed"
                          Line00000006 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031289.exe Deleted"
                          Line00000005 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031290.exe Detected with: Adware.Navipromo.BZC"
                          Line00000004 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031290.exe Disinfection failed"
                          Line00000003 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031290.exe Deleted"
                          Line00000002 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031291.exe Detected with: Adware.Navipromo.BZC"
                          Line00000001 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031291.exe Disinfection failed"
                          Line00000000 = "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP175\A0031291.exe Deleted"
                      • 1
                      • 2
                      • 3