Alors,
Impossible de désinstaller WebRebates et Websearch, ils sont inexistants.
J'ai pu effacer C:\Windows\system32\nsvsvc et C:\Windows\system32\picsvr, les autres n'existaient pas.
Voici le rapport d'AVG Anti-Spyware :
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 23:47:33 07/12/2006
+ Résultat de l'analyse:
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP255\A0032746.exe -> Adware.404Search : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP280\A0034132.exe -> Adware.AdWast : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\__unin__.exe -> Adware.Altnet : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\asmfiles.cab/asm.exe -> Adware.Altnet : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\asmfiles.cab/asmps.dll -> Adware.Altnet : Ignoré.
C:\Documents and Settings\David Le Guével\Mes documents\kazaa_setup.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP253\A0032685.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP255\A0032735.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032770.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032774.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032778.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032779.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032780.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032782.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032783.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032784.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032785.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032787.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033060.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033064.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033068.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033069.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033070.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033072.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033073.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033074.dll -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033075.exe -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033077.dll -> Adware.Altnet : Ignoré.
C:\WINDOWS\Temp\Altnet -> Adware.Altnet : Ignoré.
C:\WINDOWS\Temp\Altnet\pmfiles.cab -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM25.ADM25.1 -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM4.ADM4.1 -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\TopSearch.TSLink -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\TopSearch.TSLink.1 -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CLSID -> Adware.Altnet : Ignoré.
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CurVer -> Adware.Altnet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP255\A0032739.dll -> Adware.BrilliantDigital : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032772.dll -> Adware.BrilliantDigital : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033062.dll -> Adware.BrilliantDigital : Ignoré.
HKLM\SOFTWARE\Classes\AdRoar.Band -> Adware.CPR : Ignoré.
HKLM\SOFTWARE\Classes\AdRoar.Band.1 -> Adware.CPR : Ignoré.
HKLM\SOFTWARE\Classes\AdRoar.Band\CLSID -> Adware.CPR : Ignoré.
HKLM\SOFTWARE\Classes\AdRoar.Band\CurVer -> Adware.CPR : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\cd_clint.dll -> Adware.Cydoor : Ignoré.
C:\WINDOWS\system32\cd_clint.dll -> Adware.Cydoor : Ignoré.
HKLM\SOFTWARE\Cydoor -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_0\Level_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_0\Level_0\Seqn_1068 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_0\Level_0\Seqn_1074 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_1 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_1\Level_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4492 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4496 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4543 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_2 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_2\Level_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_2\Level_0\Seqn_1068 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_2\Level_0\Seqn_1074 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_3 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_3\Level_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_3\Level_0\Seqn_1068 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_3\Level_0\Seqn_1074 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4\Level_0 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1116 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1524 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1553 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1641 -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Services -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Services\Queue -> Adware.Cydoor : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Cydoor\Adwr_329\Services\Status -> Adware.Cydoor : Ignoré.
HKLM\SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1 -> Adware.Delfin : Ignoré.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Adware.Delfin : Ignoré.
HKLM\SOFTWARE\Mvu -> Adware.Delfin : Ignoré.
HKLM\SOFTWARE\picsvr -> Adware.Delfin : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Mvu -> Adware.Delfin : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\picsvr -> Adware.Delfin : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\uppicsvr.exe -> Adware.DelphinMedia.Viewer : Ignoré.
C:\Program Files\Fichiers communs\Uninstall Information\RemoveDisplayUtility.exe -> Adware.DelphinMediaViewer : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP281\A0034402.ocx -> Adware.DelphinMediaViewer : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP281\A0034449.dll -> Adware.DelphinMediaViewer : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP281\A0034450.exe -> Adware.DelphinMediaViewer : Ignoré.
C:\Program Files\INSTAFINK -> Adware.Gator : Ignoré.
C:\Program Files\INSTAFINK\instafink.dll -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\AppInfo -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\CMEII -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\GInternet -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\GInternet\Proxy -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_gi -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_gs -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_trickle -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_ts -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\dyn\GUS -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\Gator\stat -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\trickles -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\trickles\TRICKLER_6104 -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\trickles\TRICKLER_6104\Trickler -> Adware.Gator : Ignoré.
HKLM\SOFTWARE\Gator.com\trickles\TRICKLER_6104\Trickler\trickle.gator.com:80/download/trickler6.cfg -> Adware.Gator : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP280\A0034130.exe -> Adware.HelpExpress : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP280\A0034131.exe -> Adware.HelpExpress : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033085.DLL -> Adware.IESearch : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP260\A0033115.dll -> Adware.IESearch : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033055.exe -> Adware.NavExcel : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033056.dll -> Adware.NavExcel : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033057.dll -> Adware.NavExcel : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\NavExcel Ltd -> Adware.NavExcel : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033052.cpl -> Adware.P2PNet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033053.exe -> Adware.P2PNet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033084.DLL -> Adware.P2PNet : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP256\A0032803.dll -> Adware.RXToolbar : Ignoré.
C:\System Volume Information\_restore{9AE25207-D0F3-45D6-8A28-2B738070A4D5}\RP259\A0033083.dll -> Adware.RXToolbar : Ignoré.
HKU\S-1-5-21-2028317691-3064015492-198249261-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Ignoré.
C:\Program Files\Fichiers communs\WinFixer 2005\FCrXML.dll -> Adware.Winfixer : Ignoré.
C:\Documents and Settings\David Le Guével\Mes documents\Transfert\Transfert 2\cdrw.zip/freemp3z.exe -> Dialer.Generic : Ignoré.
C:\Documents and Settings\David Le Guével\Mes documents\Transfert\Transfert 2\plugin_required.EXE -> Downloader.Swizzor.au : Ignoré.
C:\Documents and Settings\David Le Guével\Mes documents\Transfert\Transfert 2\Papillon.exe -> Not-A-Virus.BadJoke.Win32.Anywork : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david_le_guével@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@admarketplace[1].txt -> TrackingCookie.Admarketplace : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@advertising[1].txt -> TrackingCookie.Advertising : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@adviva[1].txt -> TrackingCookie.Adviva : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david_le_guével@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@casinodelrio[1].txt -> TrackingCookie.Casinodelrio : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@www.casinodelrio[2].txt -> TrackingCookie.Casinodelrio : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@casinotropez[1].txt -> TrackingCookie.Casinotropez : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@www.casinotropez[2].txt -> TrackingCookie.Casinotropez : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@estat[1].txt -> TrackingCookie.Estat : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@as1.falkag[2].txt -> TrackingCookie.Falkag : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@fastclick[2].txt -> TrackingCookie.Fastclick : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@www.goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@ehg-telecomitalia.hitbox[2].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@hitbox[1].txt -> TrackingCookie.Hitbox : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@need2find[2].txt -> TrackingCookie.Need2find : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@questionmarket[2].txt -> TrackingCookie.Questionmarket : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@edge.ru4[2].txt -> TrackingCookie.Ru4 : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david_le_guével@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@statcounter[1].txt -> TrackingCookie.Statcounter : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@weborama[1].txt -> TrackingCookie.Weborama : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Ignoré.
C:\Documents and Settings\David Le Guével\Cookies\david le guével@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignoré.
C:\Documents and Settings\David Le Guével\Local Settings\Temp\Cookies\david le guével@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignoré.
Fin du rapport
Voici le rapport Hijackthis généré par la suite :
Logfile of HijackThis v1.99.1
Scan saved at 23:48:56, on 07/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Palm\HOTSYNC.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\DOCUME~1\DAVIDL~1\LOCALS~1\Temp\Répertoire temporaire 6 pour hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.carrefour.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.carrefour.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\AvA\Watch.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI699F~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?5982483c79e94a0fa045f4f25a575bc
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?5982483c79e94a0fa045f4f25a575bc
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI699F~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{352C7D4D-000F-4D59-A30C-125EB34F3FBC}: NameServer = 212.27.54.252 212.27.53.252
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
Et maintenant, je t'écoute !
Par contre, penses-tu que que CryptExe puisse être à l'origine de mes démarrages difficiles (du style alim qui s'envoie en l'air, mon alim à 6 mois seulement)
Ce soir, pendant la suppression des dossiers, AVG m'a annoncé la présence de CryptExe dans C:Windows\system32\mnigowvejp.exe si cela peut t'aider.
J'attends ta réponse, merci.
@+