J'ai suivis tes instructions à la ligne, et je crois que le probleme est resolut.
Super, merci beaucoup.
Je te mets quand meme le rapport BitDefender et le log HiJackThis et attends tes commentaires avant d'annoncer officiellemen "Probleme Résolu" !
MErci encore pour tes differents conseils.
[General]
App = "BitDefender Online Scanner v8"
Date = 28:12:2007
Time = 10:00:08
Scan Path = C:\;D:\;E:\;
[Engines Info]
Virus Definitions = 884591
Engine build = "AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)"
Scan plugins = 14
Archive plugins = 38
Unpack plugins = 7
E-mail plugins = 6
System plugins = 1
[Scan Statistics]
Folders = 16803
Files = 588770
Archives = 7349
Packed files = 27933
Identified viruses = 9
Infected files = 52
Warnings = 0
Suspect files = 0
Disinfected files = 0
Deleted files = 81
Copied files = 0
Moved files = 0
Renamed files = 0
I/O Errors = 57
[Scan Settings]
SecondAction = Delete
FirstAction = Disinfect
Heuristics = 1
Enable Warnings = 1
Exclude Ext =
Extensions = *;
Scan Emails = 1
Scan Archives = 1
Scan Packed = 1
Scan Files = 1
Scan Boot = 1
Verify Memory = 0
[Scan Results]
Line00000144 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100000\477BCBBC.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000143 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100000\477BCBBC.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000142 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100000\477BCBBC.VBN=>(Quarantine-PE) Supprimé"
Line00000141 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100001\477BCEC1.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000140 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100001\477BCEC1.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000139 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100001\477BCEC1.VBN=>(Quarantine-PE) Supprimé"
Line00000138 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100002\477BD768.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000137 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100002\477BD768.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000136 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01100002\477BD768.VBN=>(Quarantine-PE) Supprimé"
Line00000135 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01500002\47793C16.VBN=>(Quarantine-PE) Infecté par: Trojan.Agent.VB.H"
Line00000134 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01500002\47793C16.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000133 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01500002\47793C16.VBN=>(Quarantine-PE) Supprimé"
Line00000132 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09DC0004\4FFE5777.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000131 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09DC0004\4FFE5777.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000130 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09DC0004\4FFE5777.VBN=>(Quarantine-PE) Supprimé"
Line00000129 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00000\4FFBB918.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000128 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00000\4FFBB918.VBN=>(Quarantine-PE) Supprimé"
Line00000127 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00001\4FFBB923.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000126 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00001\4FFBB923.VBN=>(Quarantine-PE) Supprimé"
Line00000125 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00002\4FFBE3D8.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000124 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00002\4FFBE3D8.VBN=>(Quarantine-PE) Supprimé"
Line00000123 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00003\4FFBE3E3.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000122 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00003\4FFBE3E3.VBN=>(Quarantine-PE) Supprimé"
Line00000121 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00004\4FFBE987.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000120 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00004\4FFBE987.VBN=>(Quarantine-PE) Supprimé"
Line00000119 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00005\4FFBE993.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000118 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB00005\4FFBE993.VBN=>(Quarantine-PE) Supprimé"
Line00000117 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40000.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000116 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40000.VBN=>(Quarantine-PE) Supprimé"
Line00000115 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40001.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000114 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40001.VBN=>(Quarantine-PE) Supprimé"
Line00000113 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40002.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000112 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40002.VBN=>(Quarantine-PE) Supprimé"
Line00000111 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40003.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000110 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40003.VBN=>(Quarantine-PE) Supprimé"
Line00000109 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40004.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000108 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DB40004.VBN=>(Quarantine-PE) Supprimé"
Line00000107 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00002\4FF26883.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000106 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00002\4FF26883.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000105 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00002\4FF26883.VBN=>(Quarantine-PE) Supprimé"
Line00000104 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00003\4FF2688E.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000103 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00003\4FF2688E.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000102 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00003\4FF2688E.VBN=>(Quarantine-PE) Supprimé"
Line00000101 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00004\4FF2689A.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000100 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00004\4FF2689A.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000099 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00004\4FF2689A.VBN=>(Quarantine-PE) Supprimé"
Line00000098 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00005\4FF268A6.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000097 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00005\4FF268A6.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000096 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00005\4FF268A6.VBN=>(Quarantine-PE) Supprimé"
Line00000095 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00006\4FF268B2.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000094 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00006\4FF268B2.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000093 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00006\4FF268B2.VBN=>(Quarantine-PE) Supprimé"
Line00000092 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00007\4FF268BE.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000091 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00007\4FF268BE.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000090 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00007\4FF268BE.VBN=>(Quarantine-PE) Supprimé"
Line00000089 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00008\4FF268C9.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000088 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00008\4FF268C9.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000087 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00008\4FF268C9.VBN=>(Quarantine-PE) Supprimé"
Line00000086 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00009\4FF26BDF.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000085 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00009\4FF26BDF.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000084 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA00009\4FF26BDF.VBN=>(Quarantine-PE) Supprimé"
Line00000083 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000A\4FF26FD6.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000082 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000A\4FF26FD6.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000081 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000A\4FF26FD6.VBN=>(Quarantine-PE) Supprimé"
Line00000080 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000B\4FF26FE1.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000079 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000B\4FF26FE1.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000078 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000B\4FF26FE1.VBN=>(Quarantine-PE) Supprimé"
Line00000077 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000C\4FF26FEC.VBN=>(Quarantine-PE) Infecté par: Packer.Malware.NSAnti.J"
Line00000076 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000C\4FF26FEC.VBN=>(Quarantine-PE) Echec de la désinfection"
Line00000075 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EA0000C\4FF26FEC.VBN=>(Quarantine-PE) Supprimé"
Line00000074 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF80000\4FF97C8E.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000073 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF80000\4FF97C8E.VBN=>(Quarantine-PE) Supprimé"
Line00000072 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF80001\4FF97CA2.VBN=>(Quarantine-PE) Infecté par: Trojan.PWS.Agent.RZU"
Line00000071 = "C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF80001\4FF97CA2.VBN=>(Quarantine-PE) Supprimé"
Line00000070 = "C:\dosocom.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000069 = "C:\dosocom.com Echec de la désinfection"
Line00000068 = "C:\dosocom.com Supprimé"
Line00000067 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000001.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000066 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000001.com Echec de la désinfection"
Line00000065 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000001.com Supprimé"
Line00000064 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000016.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000063 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000016.dll Echec de la désinfection"
Line00000062 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000016.dll Supprimé"
Line00000061 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000021.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000060 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000021.com Echec de la désinfection"
Line00000059 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000021.com Supprimé"
Line00000058 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000036.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000057 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000036.dll Echec de la désinfection"
Line00000056 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000036.dll Supprimé"
Line00000055 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000041.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000054 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000041.com Echec de la désinfection"
Line00000053 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000041.com Supprimé"
Line00000052 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000067.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000051 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000067.dll Echec de la désinfection"
Line00000050 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000067.dll Supprimé"
Line00000049 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000072.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000048 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000072.com Echec de la désinfection"
Line00000047 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000072.com Supprimé"
Line00000046 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000076.exe Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000045 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000076.exe Echec de la désinfection"
Line00000044 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000076.exe Supprimé"
Line00000043 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000077.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000042 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000077.dll Echec de la désinfection"
Line00000041 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000077.dll Supprimé"
Line00000040 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP2\A0000127.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000039 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP2\A0000127.dll Echec de la désinfection"
Line00000038 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP2\A0000127.dll Supprimé"
Line00000037 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000431.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000036 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000431.com Echec de la désinfection"
Line00000035 = "C:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000431.com Supprimé"
Line00000034 = "C:\upload_moi_TOSHIBA-USER.tar.gz=>upload_moi.tar=>WINDOWS/System32/amvo0.dll Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000033 = "C:\upload_moi_TOSHIBA-USER.tar.gz=>upload_moi.tar=>WINDOWS/System32/amvo0.dll Echec de la désinfection"
Line00000032 = "C:\upload_moi_TOSHIBA-USER.tar.gz=>upload_moi.tar=>WINDOWS/System32/amvo0.dll Supprimé"
Line00000031 = "C:\upload_moi_TOSHIBA-USER.tar.gz=>upload_moi.tar Mis à jour"
Line00000030 = "C:\upload_moi_TOSHIBA-USER.tar.gz Mis à jour"
Line00000029 = "C:\usdeiect.com Infecté par: Trojan.PWS.OnLineGames.NUG"
Line00000028 = "C:\usdeiect.com Echec de la désinfection"
Line00000027 = "C:\usdeiect.com Supprimé"
Line00000026 = "C:\uxdeiect.com Infecté par: Trojan.PWS.OnLineGames.NTY"
Line00000025 = "C:\uxdeiect.com Echec de la désinfection"
Line00000024 = "C:\uxdeiect.com Supprimé"
Line00000023 = "D:\dosocom.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000022 = "D:\dosocom.com Echec de la désinfection"
Line00000021 = "D:\dosocom.com Supprimé"
Line00000020 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000003.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000019 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000003.com Echec de la désinfection"
Line00000018 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000003.com Supprimé"
Line00000017 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000023.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000016 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000023.com Echec de la désinfection"
Line00000015 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000023.com Supprimé"
Line00000014 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000043.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000013 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000043.com Echec de la désinfection"
Line00000012 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000043.com Supprimé"
Line00000011 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000074.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000010 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000074.com Echec de la désinfection"
Line00000009 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP1\A0000074.com Supprimé"
Line00000008 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000434.com Infecté par: Trojan.PWS.OnLineGames.NUH"
Line00000007 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000434.com Echec de la désinfection"
Line00000006 = "D:\System Volume Information\_restore{4D63D73D-1437-47A2-A4E0-B26B4D4FEF6A}\RP8\A0000434.com Supprimé"
Line00000005 = "D:\usdeiect.com Infecté par: Trojan.PWS.OnLineGames.NUG"
Line00000004 = "D:\usdeiect.com Echec de la désinfection"
Line00000003 = "D:\usdeiect.com Supprimé"
Line00000002 = "D:\uxdeiect.com Infecté par: Trojan.PWS.OnLineGames.NTY"
Line00000001 = "D:\uxdeiect.com Echec de la désinfection"
Line00000000 = "D:\uxdeiect.com Supprimé"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:40 a.m., on 28/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Archivos de programa\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Archivos de programa\Symantec AntiVirus\Rtvscan.exe
C:\ARCHIV~1\SYMANT~1\VPTray.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Archivos de programa\TOSHIBA\Tvs\TvsTray.exe
C:\Archivos de programa\TOSHIBA\TouchPad\TPTray.exe
C:\Archivos de programa\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Archivos de programa\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\RTHDCPL.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\Archivos de programa\TOSHIBA\Touch and Launch\PadExe.exe
C:\Archivos de programa\TOSHIBA\ConfigFree\NDSTray.exe
C:\Archivos de programa\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Archivos de programa\TOSHIBA\E-KEY\CeEKey.exe
C:\Archivos de programa\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe
C:\Archivos de programa\Apoint2K\Apntex.exe
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Archivos de programa\Skype\Phone\Skype.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\RAMASST.exe
C:\Archivos de programa\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Archivos de programa\MSN Messenger\usnsvc.exe
C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\User\Escritorio\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\ARCHIV~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [Tvs] C:\Archivos de programa\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Archivos de programa\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Archivos de programa\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SmoothView] C:\Archivos de programa\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [PadTouch] C:\Archivos de programa\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Archivos de programa\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Archivos de programa\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [CeEKEY] C:\Archivos de programa\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Apoint] C:\Archivos de programa\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [FTP Server] C:\TYPSOF~1\ftpserv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Archivos de programa\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Archivos de programa\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=
http://www.toshibalatino.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARCHIV~1\ARCHIV~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Archivos de programa\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\ARCHIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Archivos de programa\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Archivos de programa\Symantec AntiVirus\Rtvscan.exe
Voici le rapport Navilog comme demandé.
J'attends tes instructions avec impatience !!
Merci d'avance.
Search Navipromo version 3.3.8 commencé le 26/12/2007 à 6:24:50.29
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Archivos de programa\navilog1
Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO
Microsoft Windows XP [Versi¢n 5.1.2600]
Internet Explorer : 6.0.2900.2180
Système de fichiers : NTFS
Executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans C:\WINDOWS ***
*** Recherche dossiers dans C:\Archivos de programa ***
*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\DATOSD~1 ***
*** Recherche dossiers dans "C:\Documents and Settings\User\datos de programa" ***
*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENINI~1\PROGRA~1 ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Aucun Fichier trouvé
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans C:\WINDOWS\system32 *
* Recherche dans "C:\Documents and Settings\User\configuraci¾n local\datos de programa" *
gnc.exe absent, Recherche non effectuÚ dans "C:\Documents and Settings\User\configuraci¾n local\datos de programa" !
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans C:\WINDOWS\system32 :
* Dans "C:\Documents and Settings\User\configuraci¾n local\datos de programa" :
3)Recherche Certificats :
Certificat Egroup absent !
4)Recherche fichiers connus :
*** Analyse terminée le 26/12/2007 à 6:36:24.26 ***