Salut,
J'ai déplacé CCM.exe, est-ce que c'est ok?
Hier, aprés avoir exécuté virtumondo, tout c'est effacé ( sauf image fond d'écran) et c'est resté bloqué comme ça jusqu'a ce que je débranche/rebranche.(ça veut dire quoi?).
Je te dis à bientôt.
Voici les rapports:
[02/23/2008, 21:03:02] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RACHEL\Bureau\VirtumundoBeGone.exe" )
[02/23/2008, 21:03:49] - User choose NOT to continue. Exiting...
[02/23/2008, 21:07:50] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RACHEL\Bureau\VirtumundoBeGone.exe" )
[02/23/2008, 21:07:52] - Detected System Information:
[02/23/2008, 21:07:52] - Windows Version: 5.1.2600, Service Pack 2
[02/23/2008, 21:07:52] - Current Username: RACHEL (Admin)
[02/23/2008, 21:07:52] - Windows is in NORMAL mode.
[02/23/2008, 21:07:52] - Searching for Browser Helper Objects:
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\gebcd
[02/23/2008, 21:07:52] - Found: HKLM\...\Winlogon\Notify\gebcd - This is probably Virtumundo.
[02/23/2008, 21:07:52] - Assigning {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} MSEvents Object
[02/23/2008, 21:07:52] - BHO list has been changed! Starting over...
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:52] - BHO 4: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:52] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:52] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - No filename found. Continuing.
[02/23/2008, 21:07:52] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:52] - BHO 7: {9269E781-6EB1-449F-8C33-098B57DD0FBA} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\vturo
[02/23/2008, 21:07:52] - Found: HKLM\...\Winlogon\Notify\vturo - This is probably Virtumundo.
[02/23/2008, 21:07:52] - Assigning {9269E781-6EB1-449F-8C33-098B57DD0FBA} MSEvents Object
[02/23/2008, 21:07:52] - BHO list has been changed! Starting over...
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:52] - BHO 4: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:52] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:52] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - No filename found. Continuing.
[02/23/2008, 21:07:52] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:52] - BHO 7: {9269E781-6EB1-449F-8C33-098B57DD0FBA} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 8: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\geedd
[02/23/2008, 21:07:52] - Found: HKLM\...\Winlogon\Notify\geedd - This is probably Virtumundo.
[02/23/2008, 21:07:52] - Assigning {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} MSEvents Object
[02/23/2008, 21:07:52] - BHO list has been changed! Starting over...
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:52] - BHO 4: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:52] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:52] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - No filename found. Continuing.
[02/23/2008, 21:07:52] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:52] - BHO 7: {9269E781-6EB1-449F-8C33-098B57DD0FBA} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 8: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 9: {C3C0859F-381E-4431-BDDF-A798C2830AFC} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/23/2008, 21:07:52] - Found: HKLM\...\Winlogon\Notify\jkhfe - This is probably Virtumundo.
[02/23/2008, 21:07:52] - Assigning {C3C0859F-381E-4431-BDDF-A798C2830AFC} MSEvents Object
[02/23/2008, 21:07:52] - BHO list has been changed! Starting over...
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:52] - BHO 4: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:52] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:52] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - No filename found. Continuing.
[02/23/2008, 21:07:52] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:52] - BHO 7: {9269E781-6EB1-449F-8C33-098B57DD0FBA} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 8: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 9: {C3C0859F-381E-4431-BDDF-A798C2830AFC} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 10: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhe
[02/23/2008, 21:07:52] - Found: HKLM\...\Winlogon\Notify\jkhhe - This is probably Virtumundo.
[02/23/2008, 21:07:52] - Assigning {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} MSEvents Object
[02/23/2008, 21:07:52] - BHO list has been changed! Starting over...
[02/23/2008, 21:07:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:52] - BHO 2: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 3: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:52] - BHO 4: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:52] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:52] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:52] - No filename found. Continuing.
[02/23/2008, 21:07:52] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:52] - BHO 7: {9269E781-6EB1-449F-8C33-098B57DD0FBA} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 8: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 9: {C3C0859F-381E-4431-BDDF-A798C2830AFC} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - BHO 10: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} (MSEvents Object)
[02/23/2008, 21:07:52] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:52] - Finished Searching Browser Helper Objects
[02/23/2008, 21:07:52] - *** Detected MSEvents Object
[02/23/2008, 21:07:52] - Trying to remove MSEvents Object...
[02/23/2008, 21:07:53] - Terminating Process: IEXPLORE.EXE
[02/23/2008, 21:07:54] - Terminating Process: RUNDLL32.EXE
[02/23/2008, 21:07:54] - Disabling Automatic Shell Restart
[02/23/2008, 21:07:54] - Terminating Process: EXPLORER.EXE
[02/23/2008, 21:07:55] - Suspending the NT Session Manager System Service
[02/23/2008, 21:07:55] - Terminating Windows NT Logon/Logoff Manager
[02/23/2008, 21:07:56] - Re-enabling Automatic Shell Restart
[02/23/2008, 21:07:56] - File to disable: C:\WINDOWS\system32\gebcd.dll
[02/23/2008, 21:07:56] - Removing HKLM\...\Browser Helper Objects\{4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1}
[02/23/2008, 21:07:56] - Removing HKCR\CLSID\{4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1}
[02/23/2008, 21:07:57] - Adding Kill Bit for ActiveX for GUID: {4509D10F-6D4A-4F0A-8DB9-F0026E70C3F1}
[02/23/2008, 21:07:57] - Deleting ATLEvents/MSEvents Registry entries
[02/23/2008, 21:07:57] - Removing HKLM\...\Winlogon\Notify\gebcd
[02/23/2008, 21:07:57] - Searching for Browser Helper Objects:
[02/23/2008, 21:07:57] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:57] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:57] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:57] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:57] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:57] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:57] - No filename found. Continuing.
[02/23/2008, 21:07:57] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:57] - BHO 6: {9269E781-6EB1-449F-8C33-098B57DD0FBA} (MSEvents Object)
[02/23/2008, 21:07:57] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:57] - BHO 7: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} (MSEvents Object)
[02/23/2008, 21:07:57] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:57] - BHO 8: {C3C0859F-381E-4431-BDDF-A798C2830AFC} (MSEvents Object)
[02/23/2008, 21:07:57] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:57] - BHO 9: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} (MSEvents Object)
[02/23/2008, 21:07:57] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:57] - Finished Searching Browser Helper Objects
[02/23/2008, 21:07:57] - *** Detected MSEvents Object
[02/23/2008, 21:07:57] - Trying to remove MSEvents Object...
[02/23/2008, 21:07:58] - Terminating Process: IEXPLORE.EXE
[02/23/2008, 21:07:58] - Terminating Process: RUNDLL32.EXE
[02/23/2008, 21:07:58] - Disabling Automatic Shell Restart
[02/23/2008, 21:07:58] - Terminating Process: EXPLORER.EXE
[02/23/2008, 21:07:58] - Suspending the NT Session Manager System Service
[02/23/2008, 21:07:59] - Terminating Windows NT Logon/Logoff Manager
[02/23/2008, 21:07:59] - Re-enabling Automatic Shell Restart
[02/23/2008, 21:07:59] - File to disable: C:\WINDOWS\system32\vturo.dll
[02/23/2008, 21:07:59] - Removing HKLM\...\Browser Helper Objects\{9269E781-6EB1-449F-8C33-098B57DD0FBA}
[02/23/2008, 21:07:59] - Removing HKCR\CLSID\{9269E781-6EB1-449F-8C33-098B57DD0FBA}
[02/23/2008, 21:07:59] - Adding Kill Bit for ActiveX for GUID: {9269E781-6EB1-449F-8C33-098B57DD0FBA}
[02/23/2008, 21:07:59] - Deleting ATLEvents/MSEvents Registry entries
[02/23/2008, 21:07:59] - Removing HKLM\...\Winlogon\Notify\vturo
[02/23/2008, 21:07:59] - Searching for Browser Helper Objects:
[02/23/2008, 21:07:59] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:07:59] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:07:59] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:07:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:59] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:07:59] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:07:59] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:07:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:07:59] - No filename found. Continuing.
[02/23/2008, 21:07:59] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:07:59] - BHO 6: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D} (MSEvents Object)
[02/23/2008, 21:07:59] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:59] - BHO 7: {C3C0859F-381E-4431-BDDF-A798C2830AFC} (MSEvents Object)
[02/23/2008, 21:07:59] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:59] - BHO 8: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} (MSEvents Object)
[02/23/2008, 21:07:59] - ALERT: Found MSEvents Object!
[02/23/2008, 21:07:59] - Finished Searching Browser Helper Objects
[02/23/2008, 21:07:59] - *** Detected MSEvents Object
[02/23/2008, 21:07:59] - Trying to remove MSEvents Object...
[02/23/2008, 21:08:00] - Terminating Process: IEXPLORE.EXE
[02/23/2008, 21:08:00] - Terminating Process: RUNDLL32.EXE
[02/23/2008, 21:08:00] - Disabling Automatic Shell Restart
[02/23/2008, 21:08:00] - Terminating Process: EXPLORER.EXE
[02/23/2008, 21:08:00] - Suspending the NT Session Manager System Service
[02/23/2008, 21:08:00] - Terminating Windows NT Logon/Logoff Manager
[02/23/2008, 21:08:00] - Re-enabling Automatic Shell Restart
[02/23/2008, 21:08:00] - File to disable: C:\WINDOWS\system32\geedd.dll
[02/23/2008, 21:08:00] - Removing HKLM\...\Browser Helper Objects\{989ACFC2-30CA-46E7-92BE-7C42F5584A9D}
[02/23/2008, 21:08:00] - Removing HKCR\CLSID\{989ACFC2-30CA-46E7-92BE-7C42F5584A9D}
[02/23/2008, 21:08:00] - Adding Kill Bit for ActiveX for GUID: {989ACFC2-30CA-46E7-92BE-7C42F5584A9D}
[02/23/2008, 21:08:00] - Deleting ATLEvents/MSEvents Registry entries
[02/23/2008, 21:08:00] - Removing HKLM\...\Winlogon\Notify\geedd
[02/23/2008, 21:08:00] - Searching for Browser Helper Objects:
[02/23/2008, 21:08:00] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:08:00] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:08:00] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:08:00] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:00] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:08:00] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:08:00] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:08:00] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:00] - No filename found. Continuing.
[02/23/2008, 21:08:00] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:08:00] - BHO 6: {C3C0859F-381E-4431-BDDF-A798C2830AFC} (MSEvents Object)
[02/23/2008, 21:08:00] - ALERT: Found MSEvents Object!
[02/23/2008, 21:08:00] - BHO 7: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} (MSEvents Object)
[02/23/2008, 21:08:00] - ALERT: Found MSEvents Object!
[02/23/2008, 21:08:00] - Finished Searching Browser Helper Objects
[02/23/2008, 21:08:00] - *** Detected MSEvents Object
[02/23/2008, 21:08:00] - Trying to remove MSEvents Object...
[02/23/2008, 21:08:01] - Terminating Process: IEXPLORE.EXE
[02/23/2008, 21:08:01] - Terminating Process: RUNDLL32.EXE
[02/23/2008, 21:08:01] - Disabling Automatic Shell Restart
[02/23/2008, 21:08:01] - Terminating Process: EXPLORER.EXE
[02/23/2008, 21:08:02] - Suspending the NT Session Manager System Service
[02/23/2008, 21:08:02] - Terminating Windows NT Logon/Logoff Manager
[02/23/2008, 21:08:02] - Re-enabling Automatic Shell Restart
[02/23/2008, 21:08:02] - File to disable: C:\WINDOWS\system32\jkhfe.dll
[02/23/2008, 21:08:02] - Removing HKLM\...\Browser Helper Objects\{C3C0859F-381E-4431-BDDF-A798C2830AFC}
[02/23/2008, 21:08:02] - Removing HKCR\CLSID\{C3C0859F-381E-4431-BDDF-A798C2830AFC}
[02/23/2008, 21:08:02] - Adding Kill Bit for ActiveX for GUID: {C3C0859F-381E-4431-BDDF-A798C2830AFC}
[02/23/2008, 21:08:02] - Deleting ATLEvents/MSEvents Registry entries
[02/23/2008, 21:08:02] - Removing HKLM\...\Winlogon\Notify\jkhfe
[02/23/2008, 21:08:02] - Searching for Browser Helper Objects:
[02/23/2008, 21:08:02] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:08:02] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:08:02] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:08:02] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:02] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:08:02] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:08:02] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:08:02] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:02] - No filename found. Continuing.
[02/23/2008, 21:08:02] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:08:02] - BHO 6: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3} (MSEvents Object)
[02/23/2008, 21:08:02] - ALERT: Found MSEvents Object!
[02/23/2008, 21:08:02] - Finished Searching Browser Helper Objects
[02/23/2008, 21:08:02] - *** Detected MSEvents Object
[02/23/2008, 21:08:02] - Trying to remove MSEvents Object...
[02/23/2008, 21:08:03] - Terminating Process: IEXPLORE.EXE
[02/23/2008, 21:08:03] - Terminating Process: RUNDLL32.EXE
[02/23/2008, 21:08:03] - Disabling Automatic Shell Restart
[02/23/2008, 21:08:03] - Terminating Process: EXPLORER.EXE
[02/23/2008, 21:08:03] - Suspending the NT Session Manager System Service
[02/23/2008, 21:08:03] - Terminating Windows NT Logon/Logoff Manager
[02/23/2008, 21:08:03] - Re-enabling Automatic Shell Restart
[02/23/2008, 21:08:03] - File to disable: C:\WINDOWS\system32\jkhhe.dll
[02/23/2008, 21:08:03] - Removing HKLM\...\Browser Helper Objects\{FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3}
[02/23/2008, 21:08:03] - Removing HKCR\CLSID\{FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3}
[02/23/2008, 21:08:03] - Adding Kill Bit for ActiveX for GUID: {FD576B1A-BF4A-4E3B-BAFE-F11E6D86F0F3}
[02/23/2008, 21:08:03] - Deleting ATLEvents/MSEvents Registry entries
[02/23/2008, 21:08:03] - Removing HKLM\...\Winlogon\Notify\jkhhe
[02/23/2008, 21:08:03] - Searching for Browser Helper Objects:
[02/23/2008, 21:08:03] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/23/2008, 21:08:03] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/23/2008, 21:08:03] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/23/2008, 21:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:03] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/23/2008, 21:08:03] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/23/2008, 21:08:03] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/23/2008, 21:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/23/2008, 21:08:03] - No filename found. Continuing.
[02/23/2008, 21:08:03] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/23/2008, 21:08:03] - Finished Searching Browser Helper Objects
[02/23/2008, 21:08:03] - Finishing up...
[02/23/2008, 21:08:03] - A restart is needed.
[02/23/2008, 21:08:13] - Attempting to Restart via STOP error (Blue Screen!)
[02/24/2008, 8:22:00] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\RACHEL\Bureau\VirtumundoBeGone.exe" )
[02/24/2008, 8:24:57] - Detected System Information:
[02/24/2008, 8:24:57] - Windows Version: 5.1.2600, Service Pack 2
[02/24/2008, 8:24:57] - Current Username: RACHEL (Admin)
[02/24/2008, 8:24:57] - Windows is in NORMAL mode.
[02/24/2008, 8:24:57] - Searching for Browser Helper Objects:
[02/24/2008, 8:24:57] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/24/2008, 8:24:57] - BHO 2: {59879FA4-4790-461c-A1CC-4EC4DE4CA483} (RXResultTracker Class)
[02/24/2008, 8:24:57] - BHO 3: {74179869-295F-44F7-A778-6847AB1FD513} ()
[02/24/2008, 8:24:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/24/2008, 8:24:57] - Checking for HKLM\...\Winlogon\Notify\jkhhh
[02/24/2008, 8:24:57] - Key not found: HKLM\...\Winlogon\Notify\jkhhh, continuing.
[02/24/2008, 8:24:57] - BHO 4: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/24/2008, 8:24:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/24/2008, 8:24:57] - No filename found. Continuing.
[02/24/2008, 8:24:57] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/24/2008, 8:24:57] - Finished Searching Browser Helper Objects
[02/24/2008, 8:24:57] - Finishing up...
[02/24/2008, 8:24:57] - Nothing found! Exiting...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:41:14, on 24/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
C:\Program Files\Pack Securite\Common\FSMA32.EXE
C:\Program Files\Pack Securite\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Pack Securite\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Pack Securite\Common\FCH32.EXE
C:\Program Files\Pack Securite\Common\FAMEH32.EXE
C:\Program Files\Pack Securite\Anti-Virus\fsqh.exe
C:\Program Files\Pack Securite\FSPC\fspc.exe
C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
C:\Program Files\Pack Securite\Anti-Virus\fssm32.exe
C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
C:\Program Files\Pack Securite\FSAUA\program\fsus.exe
C:\Program Files\Pack Securite\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pack Securite\Common\FSM32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Pack Securite\FSGUI\fsguidll.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\CCM.exe\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\PROGRA~1\RXTOOL~1\sfcont.dll (file missing)
O2 - BHO: (no name) - {74179869-295F-44F7-A778-6847AB1FD513} - C:\WINDOWS\system32\jkhhh.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Pack Securite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Pack Securite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pctfbwjo] c:\windows\system32\pctfbwjo.exe pctfbwjo
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Pack Securite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\PROGRA~1\RXTOOL~1\sfcont.dll
O20 - Winlogon Notify: gebca - C:\WINDOWS\system32\gebca.dll (file missing)
O20 - Winlogon Notify: geeba - C:\WINDOWS\system32\geeba.dll
O20 - Winlogon Notify: jkkji - C:\WINDOWS\system32\jkkji.dll (file missing)
O20 - Winlogon Notify: urqpmkl - urqpmkl.dll (file missing)
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Pack Securite\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Pack Securite\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Pack Securite\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Pack Securite\Common\FSMA32.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O24 - Desktop Component 0: (no name) -
http://a2.g.akamai.net/f/2/1688/1h/www.tv-radio.com/player/images/blank.gif
O24 - Desktop Component 1: (no name) -
http://www.europe2.fr/img/header/logo.gif
End of file - 6421 bytes