Suspicious MH690

Fermé
GG-81 - 21 mars 2009 à 04:52
 Utilisateur anonyme - 22 mars 2009 à 19:16
Bonjour,

Mon Norton à détecté Suspicious MH690 sur mon portable. J'ai téléchargé HijackThis et fait le scan, mais j'aurais besoin d'aide pour déchiffré le rapport que voici:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:34:15, on 2009-03-20
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Users\Alex\AppData\Local\Temp\zj1tu9skkc1b.exe
C:\Users\Alex\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp-consumer.my.aol.qc.ca/?icid=notebook
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.gateworld.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp-consumer.my.aol.qc.ca/?icid=notebook
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hp-consumer.my.aol.qc.ca/?icid=notebook
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [yahpzwhaxk2eikycz3v6j8] C:\Users\Alex\AppData\Local\Temp\w5hrxw5ltubt.exe
O4 - HKCU\..\Run: [oti8t8c8gywrihhfzk9qred] C:\Users\Alex\AppData\Local\Temp\wxmp7nhv.exe
O4 - HKCU\..\Run: [to2r7rltvwksknnqy05ex8n65h7l] C:\Users\Alex\AppData\Local\Temp\p7s2vl.exe
O4 - HKCU\..\Run: [auv85s20oyt1riccwt5ru5oi6y3ngxg86sv9tb0w79w] C:\Users\Alex\AppData\Local\Temp\obusziqtu.exe
O4 - HKCU\..\Run: [ffcakmx4dz26v0d7m1tx8rh0ml] C:\Users\Alex\AppData\Local\Temp\z81ai66on6op.exe
O4 - HKCU\..\Run: [bje8ftqtw4b04cx3o6dhylc] C:\Users\Alex\AppData\Local\Temp\kw3dexwvq7ua.exe
O4 - HKCU\..\Run: [cw8di5dd716rxczgdyonwz0hvahq133y3r5] C:\Users\Alex\AppData\Local\Temp\m6dd2oyvb.exe
O4 - HKCU\..\Run: [iacy2wcsl5eoc9v5ns9i3zhkleo4dz4i12qd79vlkpj] C:\Users\Alex\AppData\Local\Temp\ubmf1jqsf39.exe
O4 - HKCU\..\Run: [c15uyy1jox2k180dlw1ys8oduaxfc] C:\Users\Alex\AppData\Local\Temp\tuanea22x.exe
O4 - HKCU\..\Run: [es1hda0izv0] C:\Users\Alex\AppData\Local\Temp\qv45eiry.exe
O4 - HKCU\..\Run: [b0q0ad5up50a90zjs7kve] C:\Users\Alex\AppData\Local\Temp\qkbyense1r.exe
O4 - HKCU\..\Run: [w7t9ctu21s6607pp9bkdur7t71y] C:\Users\Alex\AppData\Local\Temp\ql5gxvhrt.exe
O4 - HKCU\..\Run: [i8vc5k81na3cejz34ztu3owo6hdzm3vs2rudp08o71v] C:\Users\Alex\AppData\Local\Temp\btvskt1081x4.exe
O4 - HKCU\..\Run: [ep32gtm4j02mdq5ue] C:\Users\Alex\AppData\Local\Temp\i7dswwfugq.exe
O4 - HKCU\..\Run: [f2xap8emhk] C:\Users\Alex\AppData\Local\Temp\jgb0hx9c.exe
O4 - HKCU\..\Run: [b4iaa6b07qtf8k0w5cjjhdfnwf4sfkmhjnozz] C:\Users\Alex\AppData\Local\Temp\uibjns1jh.exe
O4 - HKCU\..\Run: [vw2t9hu2ybg773ipuujh006pn8sf5eb37vrwx5wxhu] C:\Users\Alex\AppData\Local\Temp\ysuk0j2qe.exe
O4 - HKCU\..\Run: [wtr872ffv5jh4bi7q2ub097e2fk] C:\Users\Alex\AppData\Local\Temp\wt15qfft.exe
O4 - HKCU\..\Run: [cg55ptll4pe9] C:\Users\Alex\AppData\Local\Temp\fgoxf2l8ixp.exe
O4 - HKCU\..\Run: [mnspkmfu9g946il2gx2jel6aj] C:\Users\Alex\AppData\Local\Temp\kfxuoaght.exe
O4 - HKCU\..\Run: [gl15m6n6q2nnx8kolu7nb5] C:\Users\Alex\AppData\Local\Temp\gf95bj421.exe
O4 - HKCU\..\Run: [s6hapnawtl7t] C:\Users\Alex\AppData\Local\Temp\rny6x0.exe
O4 - HKCU\..\Run: [bt1un1ztusyuijlyl6f1tzi73nlf34q8sqm7tqpyeze] C:\Users\Alex\AppData\Local\Temp\kzhynajcl.exe
O4 - HKCU\..\Run: [vfrly6tucv2bk12deqntldpwk2fjss10d7uj0f22o3g] C:\Users\Alex\AppData\Local\Temp\zhbxh8n.exe
O4 - HKCU\..\Run: [qkvfjlmbhi8nit9xe5fvljhaudcpie7muigy19jir6] C:\Users\Alex\AppData\Local\Temp\z6iqlm237.exe
O4 - HKCU\..\Run: [knkbursrmftf8hm6bf1npoe0j0unsam82y0i9u4fhca] C:\Users\Alex\AppData\Local\Temp\w208k51ml1f.exe
O4 - HKCU\..\Run: [xj93lv54og9nzqxh0vzpamwsjto56z] C:\Users\Alex\AppData\Local\Temp\z6el6p.exe
O4 - HKCU\..\Run: [g02mo5aakh236dhy8c16bfox] C:\Users\Alex\AppData\Local\Temp\huk2qstrss8bn.exe
O4 - HKCU\..\Run: [lkjd0bu08oyu7ev3xznzr2k99bbkko] C:\Users\Alex\AppData\Local\Temp\odfdjb.exe
O4 - HKCU\..\Run: [ezkg4bsbuyr8zf467i7fuslfzwxsqfh] C:\Users\Alex\AppData\Local\Temp\tilu3vyrt2zq3.exe
O4 - HKCU\..\Run: [inng8s01m04yx827pjxz] C:\Users\Alex\AppData\Local\Temp\sxnpcj.exe
O4 - HKCU\..\Run: [urxi5qekp7ec6gmeaerdq] C:\Users\Alex\AppData\Local\Temp\t4qtbnm9gu6.exe
O4 - HKCU\..\Run: [p6eo8t5grsl07s990gf377] C:\Users\Alex\AppData\Local\Temp\j66u07caa6s.exe
O4 - HKCU\..\Run: [wr5whnwnyg97p8b0jnpfn] C:\Users\Alex\AppData\Local\Temp\s53nsw7g5tz.exe
O4 - HKCU\..\Run: [hy46lwpxqspkd35exbu5pi4dpltjh8kym] C:\Users\Alex\AppData\Local\Temp\rp72a1czze3.exe
O4 - HKCU\..\Run: [xzr2hh4goujf1n0ffq9ymy0r9n8flhnaxpl9] C:\Users\Alex\AppData\Local\Temp\rq1ka9iv8r.exe
O4 - HKCU\..\Run: [w4grvivskzo1axepv3kvb2th525df1nldos386z] C:\Users\Alex\AppData\Local\Temp\zj1tu9skkc1b.exe
O4 - HKCU\..\Run: [s6bo4usz6hq8] C:\Users\Alex\AppData\Local\Temp\h77aecq6avn.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWow64\Macromed\Flash\FlashUtil10a.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\STacSV64.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

15 réponses

Utilisateur anonyme
21 mars 2009 à 05:17
bonjour :

Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

- Vas dans "Démarrer" puis Panneau de configuration.
- Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
- Clique sur Continuer.
- Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
- Valide par OK et redémarre.

Tuto

ensuite :


=============================================================================================
>>>>>Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<<<<
>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<<<
=============================================================================================

Lors de son exécution,

ComboFix va vérifier si la Console de récupération Microsoft Windows est installée. Avec des infections comme celles d'aujourd'hui, il est fortement conseillé de l'avoir pré-installée sur votre PC avant toute suppression de nuisibles.
Elle vous permettra de démarrer dans un mode spécial, de récupération (réparation), qui nous permet de vous aider plus facilement si jamais votre ordinateur rencontre un problème après une tentative de nettoyage.

Suivez les invites pour permettre à ComboFix de télécharger et installer la Console de récupération Microsoft Windows

et lorsque cela vous est demandé, acceptez le Contrat de Licence Utilisateur Final pour installer la Console de récupération Microsoft Windows.

Sous XP

Sous Vista

**Note importante: Si la Console de récupération Microsoft Windows est déjà installée, ComboFix continuera ses procédures de suppression de nuisibles.


A Lire , Impératif !!!!

Télécharges Combofix :




Et important, enregistre le sous "moi.exe" sur le bureau.

Avant d'utiliser ComboFix :

? Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
? Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.


Une fois fait, sur ton bureau double-clic sur moi.exe

- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

- En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

? Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

? Reviens sur le forum, et

copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

0
Salut,

Le ComboFix que tu me propose, n'est pas compatible pour Windows Vista.
0
Utilisateur anonyme
21 mars 2009 à 23:20
si il est compatible avec Vista mais pas avec 64 bits
0
Qu'est-ce que fait alors?
0
Quand j'exécute le programme, un message d'erreur apparait disant que ComboFix est incompatible.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
22 mars 2009 à 00:14
Télécharge Superantispyware (SAS)

Choisis "enregistrer" et enregistre-le sur ton bureau.

Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

Créé une icône sur le bureau.

Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.

- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

Dans la colonne de gauche, coche C:\Fixed Drive.

Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

Pour recopier les informations sur le forum, fais ceci :

- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

- Copie son contenu dans ta réponse.


Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
0
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 03/21/2009 at 09:28 PM

Application Version : 4.25.1014

Core Rules Database Version : 3808
Trace Rules Database Version: 1763

Scan type : Complete Scan
Total Scan Time : 01:24:20

Memory items scanned : 953
Memory threats detected : 4
Registry items scanned : 7462
Registry threats detected : 7
File items scanned : 154593
File threats detected : 112

Trojan.Unknown Origin
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\YTOM6Z.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\YTOM6Z.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\HUSU55JBH3.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\HUSU55JBH3.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\H0WYQZWGM69W4.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\H0WYQZWGM69W4.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\QEA86KT7R44N.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\QEA86KT7R44N.EXE
[f2xap8emhk] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\JGB0HX9C.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\JGB0HX9C.EXE
[b4iaa6b07qtf8k0w5cjjhdfnwf4sfkmhjnozz] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\UIBJNS1JH.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\UIBJNS1JH.EXE
[cnf4sd67c0lpv5mv3uolgkwcjun7v] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\DCAG6WE48PEPA.EXE
C:\USERS\ALEX\APPDATA\LOCAL\TEMP\DCAG6WE48PEPA.EXE
[lshxrv30oi] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\H0WYQZWGM69W4.EXE
[tgks2m034e8oy4mjc] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\YTOM6Z.EXE
[paffyla2oc5u2p123hr945re8tn31g1r30j] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\HUSU55JBH3.EXE
[q9iz5x91xfhio4poksc9jv7vq7gu5pbr94svdn8g] C:\USERS\ALEX\APPDATA\LOCAL\TEMP\QEA86KT7R44N.EXE
C:\YDITVMJ.EXE
C:\Windows\Prefetch\DCAG6WE48PEPA.EXE-6B7399BD.pf

Adware.Tracking Cookie
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@vitamine.networldmedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@server.iad.liveperson[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@doubleclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@shopica[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@server.iad.liveperson[3].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@www.findstuff[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@geosign.112.2o7[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@estat[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@atdmt[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@ads.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@questionmarket[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@overture[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@trafficmp[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@adserver.adtechus[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@smartadserver[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@xiti[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@c7.zedo[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@zedo[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@advertising[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@vitamine.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@mediaplex[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@stat.dealtime[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@pro-market[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@serving-sys[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@media6degrees[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@bizrate[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@dealtime[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@adopt.euroclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@ad.yieldmanager[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@toseeka[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@bluestreak[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@interclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@revsci[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@networldmedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@tribalfusion[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@tracking.foundry42[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@counter.surfcounters[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@casalemedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@bs.serving-sys[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@specificclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@fastclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@apmebf[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@247realmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@2o7[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@3038.10026.clickshield[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@680.stats.misstrends[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@879.stats.misstrends[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ad.yieldmanager[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adbrite[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adcentriconline[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.canalblog[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.networldmedia[3].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.pointroll[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.widgetbucks[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adserver.adtechus[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adserver.aol[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adtech[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@advertising[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adviva[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@at.atwola[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@atdmt[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@bluestreak[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@bs.serving-sys[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@casalemedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@doubleclick[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ehg-mybc.hitbox[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@fastclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@fl01.ct2.comclick[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@hitbox[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@interhome.solution.weborama[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@media.photobucket[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@media6degrees[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@mediaplex[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@networldmedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@nhl.112.2o7[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@questionmarket[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@revsci[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@serving-sys[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@sexe4gay[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@sixapart.adbureau[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@smartadserver[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@specificclick[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@statcounter[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@stats.canalblog[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@statse.webtrendslive[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@tacoda[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@timeinc.122.2o7[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@tns-counter[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@tradedoubler[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@tribalfusion[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@videos-de-sexe.3x[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@vitamine.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@vitamine.networldmedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@weborama[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@www.findstuff[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@www.googleadservices[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@www.meteomedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@www.siteporno[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@xiti[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@xxx.falconstudios[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@yadro[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@zedo[1].txt
0
Utilisateur anonyme
22 mars 2009 à 03:50
relances hijackthis stp
0
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:58:39, on 2009-03-21
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\PROGRA~2\GRETECH\GOMPLA~1\GOM.exe
C:\Users\Alex\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gateworld.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files (x86)\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [yahpzwhaxk2eikycz3v6j8] C:\Users\Alex\AppData\Local\Temp\w5hrxw5ltubt.exe
O4 - HKCU\..\Run: [oti8t8c8gywrihhfzk9qred] C:\Users\Alex\AppData\Local\Temp\wxmp7nhv.exe
O4 - HKCU\..\Run: [to2r7rltvwksknnqy05ex8n65h7l] C:\Users\Alex\AppData\Local\Temp\p7s2vl.exe
O4 - HKCU\..\Run: [auv85s20oyt1riccwt5ru5oi6y3ngxg86sv9tb0w79w] C:\Users\Alex\AppData\Local\Temp\obusziqtu.exe
O4 - HKCU\..\Run: [ffcakmx4dz26v0d7m1tx8rh0ml] C:\Users\Alex\AppData\Local\Temp\z81ai66on6op.exe
O4 - HKCU\..\Run: [bje8ftqtw4b04cx3o6dhylc] C:\Users\Alex\AppData\Local\Temp\kw3dexwvq7ua.exe
O4 - HKCU\..\Run: [cw8di5dd716rxczgdyonwz0hvahq133y3r5] C:\Users\Alex\AppData\Local\Temp\m6dd2oyvb.exe
O4 - HKCU\..\Run: [iacy2wcsl5eoc9v5ns9i3zhkleo4dz4i12qd79vlkpj] C:\Users\Alex\AppData\Local\Temp\ubmf1jqsf39.exe
O4 - HKCU\..\Run: [c15uyy1jox2k180dlw1ys8oduaxfc] C:\Users\Alex\AppData\Local\Temp\tuanea22x.exe
O4 - HKCU\..\Run: [es1hda0izv0] C:\Users\Alex\AppData\Local\Temp\qv45eiry.exe
O4 - HKCU\..\Run: [b0q0ad5up50a90zjs7kve] C:\Users\Alex\AppData\Local\Temp\qkbyense1r.exe
O4 - HKCU\..\Run: [w7t9ctu21s6607pp9bkdur7t71y] C:\Users\Alex\AppData\Local\Temp\ql5gxvhrt.exe
O4 - HKCU\..\Run: [i8vc5k81na3cejz34ztu3owo6hdzm3vs2rudp08o71v] C:\Users\Alex\AppData\Local\Temp\btvskt1081x4.exe
O4 - HKCU\..\Run: [ep32gtm4j02mdq5ue] C:\Users\Alex\AppData\Local\Temp\i7dswwfugq.exe
O4 - HKCU\..\Run: [vw2t9hu2ybg773ipuujh006pn8sf5eb37vrwx5wxhu] C:\Users\Alex\AppData\Local\Temp\ysuk0j2qe.exe
O4 - HKCU\..\Run: [wtr872ffv5jh4bi7q2ub097e2fk] C:\Users\Alex\AppData\Local\Temp\wt15qfft.exe
O4 - HKCU\..\Run: [cg55ptll4pe9] C:\Users\Alex\AppData\Local\Temp\fgoxf2l8ixp.exe
O4 - HKCU\..\Run: [mnspkmfu9g946il2gx2jel6aj] C:\Users\Alex\AppData\Local\Temp\kfxuoaght.exe
O4 - HKCU\..\Run: [gl15m6n6q2nnx8kolu7nb5] C:\Users\Alex\AppData\Local\Temp\gf95bj421.exe
O4 - HKCU\..\Run: [s6hapnawtl7t] C:\Users\Alex\AppData\Local\Temp\rny6x0.exe
O4 - HKCU\..\Run: [bt1un1ztusyuijlyl6f1tzi73nlf34q8sqm7tqpyeze] C:\Users\Alex\AppData\Local\Temp\kzhynajcl.exe
O4 - HKCU\..\Run: [vfrly6tucv2bk12deqntldpwk2fjss10d7uj0f22o3g] C:\Users\Alex\AppData\Local\Temp\zhbxh8n.exe
O4 - HKCU\..\Run: [qkvfjlmbhi8nit9xe5fvljhaudcpie7muigy19jir6] C:\Users\Alex\AppData\Local\Temp\z6iqlm237.exe
O4 - HKCU\..\Run: [knkbursrmftf8hm6bf1npoe0j0unsam82y0i9u4fhca] C:\Users\Alex\AppData\Local\Temp\w208k51ml1f.exe
O4 - HKCU\..\Run: [xj93lv54og9nzqxh0vzpamwsjto56z] C:\Users\Alex\AppData\Local\Temp\z6el6p.exe
O4 - HKCU\..\Run: [g02mo5aakh236dhy8c16bfox] C:\Users\Alex\AppData\Local\Temp\huk2qstrss8bn.exe
O4 - HKCU\..\Run: [lkjd0bu08oyu7ev3xznzr2k99bbkko] C:\Users\Alex\AppData\Local\Temp\odfdjb.exe
O4 - HKCU\..\Run: [ezkg4bsbuyr8zf467i7fuslfzwxsqfh] C:\Users\Alex\AppData\Local\Temp\tilu3vyrt2zq3.exe
O4 - HKCU\..\Run: [inng8s01m04yx827pjxz] C:\Users\Alex\AppData\Local\Temp\sxnpcj.exe
O4 - HKCU\..\Run: [urxi5qekp7ec6gmeaerdq] C:\Users\Alex\AppData\Local\Temp\t4qtbnm9gu6.exe
O4 - HKCU\..\Run: [p6eo8t5grsl07s990gf377] C:\Users\Alex\AppData\Local\Temp\j66u07caa6s.exe
O4 - HKCU\..\Run: [wr5whnwnyg97p8b0jnpfn] C:\Users\Alex\AppData\Local\Temp\s53nsw7g5tz.exe
O4 - HKCU\..\Run: [hy46lwpxqspkd35exbu5pi4dpltjh8kym] C:\Users\Alex\AppData\Local\Temp\rp72a1czze3.exe
O4 - HKCU\..\Run: [xzr2hh4goujf1n0ffq9ymy0r9n8flhnaxpl9] C:\Users\Alex\AppData\Local\Temp\rq1ka9iv8r.exe
O4 - HKCU\..\Run: [w4grvivskzo1axepv3kvb2th525df1nldos386z] C:\Users\Alex\AppData\Local\Temp\zj1tu9skkc1b.exe
O4 - HKCU\..\Run: [s6bo4usz6hq8] C:\Users\Alex\AppData\Local\Temp\h77aecq6avn.exe
O4 - HKCU\..\Run: [x3ndk2kjf8a07xfkfeyt0zpdquup01hc] C:\Users\Alex\AppData\Local\Temp\kgxngew9k9x.exe
O4 - HKCU\..\Run: [p1bkevqw6ynq5lt8aku0juvlmzpk9bq73tr4rn8] C:\Users\Alex\AppData\Local\Temp\wtfmdd7qgy90.exe
O4 - HKCU\..\Run: [klkebsmgauz6l4mfhshrv1gor6o] C:\Users\Alex\AppData\Local\Temp\xalv47.exe
O4 - HKCU\..\Run: [ka5x83no9] C:\Users\Alex\AppData\Local\Temp\l2k388gl0d.exe
O4 - HKCU\..\Run: [ruml2oll8pun59mawkyxothp2k5vesyyd] C:\Users\Alex\AppData\Local\Temp\dfr4owqcj7.exe
O4 - HKCU\..\Run: [rel7w8t2evcjlvdhenaf8emqlsdcxckjcf2qcm] C:\Users\Alex\AppData\Local\Temp\iot7r7xaqqn.exe
O4 - HKCU\..\Run: [owok9wsr05motmjyc9iwsbdixsgjgx9dr] C:\Users\Alex\AppData\Local\Temp\pih8k2m862.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\AESTSr64.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\STacSV64.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~2\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
0
Utilisateur anonyme
22 mars 2009 à 04:37
ARF !!! le 64 bits !!!!!

dur-dur la !!! en plus tu es bien infecté

repasses superantispyware en mode sans échec sans prise en charge réseau
0
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 03/22/2009 at 02:07 AM

Application Version : 4.25.1014

Core Rules Database Version : 3808
Trace Rules Database Version: 1763

Scan type : Complete Scan
Total Scan Time : 01:18:07

Memory items scanned : 565
Memory threats detected : 0
Registry items scanned : 7455
Registry threats detected : 0
File items scanned : 155110
File threats detected : 19

Adware.Tracking Cookie
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\alex@atdmt[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ad.yieldmanager[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@adbrite[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@ads.widgetbucks[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@atdmt[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@fl01.ct2.comclick[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@mediaplex[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@questionmarket[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@revsci[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@smartadserver[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@specificclick[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@statcounter[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@vitamine.networldmedia[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@vitamine.networldmedia[2].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@xiti[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@yadro[1].txt
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies\Low\alex@zedo[1].txt
0
Utilisateur anonyme
22 mars 2009 à 15:26
bon ben désolé je ne suis pas assez qualifié en 64 bits pour te permettre d'aller plus loin et comme il vaut mieux eviter de te faire faire des âneries..
0
C'est aussi ce que je me disait, merci de ton aide.
0
Utilisateur anonyme
22 mars 2009 à 17:09
Mais pourquoi 64 bits !!!! lol

:)
0
Aucune idée, jle savais pas jusqu'il y a très peu de temps.
0
Utilisateur anonyme
22 mars 2009 à 19:16
bien ben en esperant que quelqu'un de plus qualifié prenne ma suite......
0