Voila le rapport de trojanremover en revanche mon problème à l'air résolu depuis que j'ai utilisé Malwarebytes' anti-malware. Mon antivirus actuel est avast
***** THE SYSTEM HAS BEEN RESTARTED *****
12/09/2008 19:56:03: Trojan Remover has been restarted
=======================================================
Removing the following registry keys:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - already removed
HKCR\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - cannot be removed
=======================================================
12/09/2008 19:56:03: Trojan Remover closed
************************************************************
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.2.2542. For information, email support@simplysup1.com
[Unregistered version]
Scan started at: 19:52:49 12 sept. 2008
Using Database v7133
Operating System: Windows XP SP3 [Windows XP Home Edition Service Pack 3 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\Nina\Application Data\Simply Super Software\Trojan Remover\
Database directory: C:\Program Files\Trojan Remover\
Logfile directory: D:\\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges
************************************************************
The following Anti-Malware program(s) are loaded:
Avast! Antivirus
************************************************************
************************************************************
19:52:50: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS
************************************************************
19:52:50: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS
************************************************************
19:52:50: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
19:52:51: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1037824 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
26624 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: avast!
Value Data: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
78008 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
--------------------
Value Name: SoundMan
Value Data: SOUNDMAN.EXE
C:\WINDOWS\SOUNDMAN.EXE
577536 bytes
Created: 09/06/2008
Modified: 17/11/2006
Company: Realtek Semiconductor Corp.
--------------------
Value Name: GrooveMonitor
Value Data: "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
31016 bytes
Created: 24/08/2007
Modified: 27/10/2006
Company: Microsoft Corporation
--------------------
Value Name: Apoint
Value Data: C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Apoint2K\Apoint.exe
-R- 147456 bytes
Created: 10/06/2008
Modified: 30/07/2003
Company: Alps Electric Co., Ltd.
--------------------
Value Name: QuickTime Task
Value Data: "C:\Program Files\QuickTime\qttask.exe" -atboottime
C:\Program Files\QuickTime\qttask.exe
413696 bytes
Created: 27/05/2008
Modified: 27/05/2008
Company: Apple Inc.
--------------------
Value Name: Adobe Reader Speed Launcher
Value Data: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
39792 bytes
Created: 11/01/2008
Modified: 11/01/2008
Company: Adobe Systems Incorporated
--------------------
Value Name: CamserviceDeluxe2
Value Data: C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe /startup
C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe
81920 bytes
Created: 20/06/2008
Modified: 10/08/2007
Company: Guillemot Corporation S.A.
--------------------
Value Name: SiS KHooker
Value Data: C:\WINDOWS\system32\khooker.exe
C:\WINDOWS\system32\khooker.exe
294912 bytes
Created: 10/07/2008
Modified: 29/05/2003
Company: Silicon Integrated Systems Corporation
--------------------
Value Name: RemoteControl
Value Data: "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
32768 bytes
Created: 10/07/2008
Modified: 15/07/2004
Company: Cyberlink Corp.
--------------------
Value Name: NeroFilterCheck
Value Data: C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\NeroCheck.exe
155648 bytes
Created: 10/07/2008
Modified: 09/07/2001
Company: Ahead Software Gmbh
--------------------
Value Name:
Value Data:
Blank entry: []
--------------------
Value Name: Sony Ericsson PC Suite
Value Data: "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
-R- 159744 bytes
Created: 26/10/2005
Modified: 26/10/2005
Company: Sony Ericsson Mobile Communications AB
--------------------
Value Name: AppleSyncNotifier
Value Data: C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
116040 bytes
Created: 10/07/2008
Modified: 10/07/2008
Company: Apple Inc.
--------------------
Value Name: iTunesHelper
Value Data: "C:\Program Files\iTunes\iTunesHelper.exe"
C:\Program Files\iTunes\iTunesHelper.exe
289064 bytes
Created: 30/07/2008
Modified: 30/07/2008
Company: Apple Inc.
--------------------
Value Name: TrojanScanner
Value Data: C:\Program Files\Trojan Remover\Trjscan.exe /boot
C:\Program Files\Trojan Remover\Trjscan.exe
917072 bytes
Created: 12/09/2008
Modified: 04/09/2008
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: ccleaner
Value Data: "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
C:\Program Files\CCleaner\CCleaner.exe
1189104 bytes
Created: 23/04/2008
Modified: 23/04/2008
Company: Piriform Ltd
--------------------
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Value Name: MsnMsgr
Value Data: "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
5724184 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
--------------------
Value Name: EPSON Stylus DX4400 Series
Value Data: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\WINDOWS\TEMP\E_SA5.tmp" /EF "HKCU"
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
179200 bytes
Created: 10/07/2008
Modified: 25/01/2007
Company: SEIKO EPSON CORPORATION
--------------------
Value Name:
Value Data:
Blank entry: []
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
************************************************************
19:52:55: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
ValueName: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}
Value: Groove GFS Stub Execution Hook
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
2210608 bytes
Created: 24/08/2007
Modified: 27/10/2006
Company: Microsoft Corporation
----------
************************************************************
19:52:55: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
19:52:56: Scanning -----ACTIVE SCREENSAVER-----
ScreenSaver: C:\WINDOWS\System32\ssmypics.scr
C:\WINDOWS\System32\ssmypics.scr
47104 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
************************************************************
19:52:56: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {6BF52A52-394A-11d3-B153-00C04F79FAA6}
Path: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub
C:\WINDOWS\INF\wmp11.inf
2441 bytes
Created: 03/11/2006
Modified: 03/11/2006
Company:
----------
************************************************************
19:52:57: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: AppMgmt
%SystemRoot%\System32\appmgmts.dll - file is globally excluded (file cannot be found)
--------------------
************************************************************
19:53:00: Scanning ----- SERVICES REGISTRY KEYS -----
Key: ApfiltrService
ImagePath: system32\DRIVERS\Apfiltr.sys
C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
-R- 92904 bytes
Created: 10/06/2008
Modified: 30/07/2003
Company: Alps Electric Co., Ltd.
----------
Key: Apple Mobile Device
ImagePath: "C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
116040 bytes
Created: 22/07/2008
Modified: 22/07/2008
Company: Apple Inc.
----------
Key: aswFsBlk
ImagePath: system32\DRIVERS\aswFsBlk.sys
C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
20560 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
----------
Key: aswUpdSv
ImagePath: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
16056 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
----------
Key: avast! Antivirus
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
C:\Program Files\Alwil Software\Avast4\ashServ.exe
147640 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
----------
Key: avast! Mail Scanner
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
250040 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
----------
Key: avast! Web Scanner
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
348344 bytes
Created: 09/06/2008
Modified: 23/07/2008
Company: ALWIL Software
----------
Key: camfilt2
ImagePath: system32\DRIVERS\camfilt2.sys
C:\WINDOWS\system32\DRIVERS\camfilt2.sys
94720 bytes
Created: 20/06/2008
Modified: 06/08/2007
Company: Guillemot Corporation
----------
Key: CBTNDIS5
ImagePath: \??\C:\WINDOWS\system32\CBTNDIS5.SYS
C:\WINDOWS\system32\CBTNDIS5.SYS
17142 bytes
Created: 10/06/2008
Modified: 16/07/2003
Company: Printing Communications Assoc., Inc. (PCAUSA)
----------
Key: NSCIRDA
ImagePath: System32\DRIVERS\nscirda.sys
C:\WINDOWS\System32\DRIVERS\nscirda.sys
28672 bytes
Created: 09/06/2008
Modified: 13/04/2008
Company: National Semiconductor Corporation
----------
Key: odserv
ImagePath: "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE"
C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE
441136 bytes
Created: 26/10/2006
Modified: 26/10/2006
Company: Microsoft Corporation
----------
Key: odysseyIM3
ImagePath: system32\DRIVERS\odysseyIM3.sys
C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
-R- 62673 bytes
Created: 10/06/2008
Modified: 14/05/2003
Company: Funk Software, Inc.
----------
Key: ose
ImagePath: "C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE"
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
145184 bytes
Created: 26/10/2006
Modified: 26/10/2006
Company: Microsoft Corporation
----------
Key: PRISM_A00
ImagePath: system32\DRIVERS\WL54CB.sys
C:\WINDOWS\system32\DRIVERS\WL54CB.sys
-R- 391008 bytes
Created: 12/06/2008
Modified: 07/04/2004
Company: Wireless Communications Corporation
----------
Key: RecAgent
ImagePath: System32\DRIVERS\RecAgent.sys
C:\WINDOWS\System32\DRIVERS\RecAgent.sys
13776 bytes
Created: 10/06/2008
Modified: 03/08/2004
Company: Smart Link
----------
Key: rtl8139
ImagePath: system32\DRIVERS\R8139n51.SYS
C:\WINDOWS\system32\DRIVERS\R8139n51.SYS
46976 bytes
Created: 10/06/2008
Modified: 30/07/2003
Company: Realtek Semiconductor Corporation
----------
Key: SiS315
ImagePath: system32\DRIVERS\sisgrp.sys
C:\WINDOWS\system32\DRIVERS\sisgrp.sys
397824 bytes
Created: 10/07/2008
Modified: 30/07/2003
Company: Silicon Integrated Systems Corporation
----------
Key: sisagp
ImagePath: system32\DRIVERS\SISAGPX.sys
C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
-R- 30720 bytes
Created: 10/07/2008
Modified: 30/07/2003
Company: Silicon Integrated Systems Corporation
----------
Key: SiSkp
ImagePath: system32\drivers\srvkp.sys
C:\WINDOWS\system32\drivers\srvkp.sys
-R- 10624 bytes
Created: 10/07/2008
Modified: 30/07/2003
Company: Silicon Integrated Systems Corporation
----------
Key: SNPSTD3
ImagePath: system32\DRIVERS\snpstd3.sys
C:\WINDOWS\system32\DRIVERS\snpstd3.sys
10371072 bytes
Created: 20/06/2008
Modified: 17/07/2007
Company: Sonix Co. Ltd.
----------
Key: SwPrv
ImagePath: C:\WINDOWS\System32\dllhost.exe /Processid:{DDDF1380-3602-4E5A-8B76-BA42742E1B23}
C:\WINDOWS\System32\dllhost.exe
5120 bytes
Created: 28/08/2001
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: usnjsvc
ImagePath: "C:\Program Files\Windows Live\Messenger\usnsvc.exe"
C:\Program Files\Windows Live\Messenger\usnsvc.exe
98328 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
----------
Key: w300bus
ImagePath: system32\DRIVERS\w300bus.sys
C:\WINDOWS\system32\DRIVERS\w300bus.sys
-R- 60800 bytes
Created: 06/09/2008
Modified: 13/03/2006
Company: MCCI
----------
Key: w300mdfl
ImagePath: system32\DRIVERS\w300mdfl.sys
C:\WINDOWS\system32\DRIVERS\w300mdfl.sys
-R- 9264 bytes
Created: 06/09/2008
Modified: 13/03/2006
Company: MCCI
----------
Key: w300mdm
ImagePath: system32\DRIVERS\w300mdm.sys
C:\WINDOWS\system32\DRIVERS\w300mdm.sys
-R- 96352 bytes
Created: 06/09/2008
Modified: 13/03/2006
Company: MCCI
----------
Key: WLSetupSvc
ImagePath: "C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
266240 bytes
Created: 25/10/2007
Modified: 25/10/2007
Company: Microsoft Corporation
----------
************************************************************
19:53:13: Scanning -----VXD ENTRIES-----
************************************************************
19:53:13: Scanning ----- WINLOGON\NOTIFY DLLS -----
************************************************************
19:53:13: Scanning ----- CONTEXTMENUHANDLERS -----
Key: avast
CLSID: {472083B0-C522-11CF-8763-00608CC02F24}
Path: C:\Program Files\Alwil Software\Avast4\ashShell.dll
C:\Program Files\Alwil Software\Avast4\ashShell.dll
73912 bytes
Created: 09/06/2008
Modified: 19/07/2008
Company: ALWIL Software
----------
Key: EPPShellEx
CLSID: {509FE1AF-ADD5-49EC-BC55-7CF81FD16E78}
Path: C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll
C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll
69632 bytes
Created: 10/07/2008
Modified: 13/04/2006
Company: SEIKO EPSON CORPORATION
----------
Key: XXX Groove GFS Context Menu Handler XXX
CLSID: {6C467336-8281-4E60-8204-430CED96822D}
Path: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
2210608 bytes
Created: 24/08/2007
Modified: 27/10/2006
Company: Microsoft Corporation
----------
************************************************************
19:53:14: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {F9DB5320-233E-11D1-9F84-707F02C10627}
File: C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
372736 bytes
Created: 10/05/2007
Modified: 10/05/2007
Company: Adobe Systems, Inc.
----------
************************************************************
19:53:14: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {02478D38-C3F9-4efb-9B51-7695ECA05670}
BHO: C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
882416 bytes
Created: 28/07/2008
Modified: 28/07/2008
Company: Yahoo! Inc.
----------
Key: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
BHO: C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - this BHO was being loaded by the following key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - this key has been removed [file not found to scan]
C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - this BHO is referenced by the following key:
HKEY_CLASSES_ROOT\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - Trojan Remover was unable to remove this key
----------
Key: {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
BHO: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
Key: {9030D464-4C02-4ABF-8ECC-5164760863C6}
BHO: C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
328752 bytes
Created: 20/09/2007
Modified: 20/09/2007
Company: Microsoft Corporation
----------
Key: {988B07F5-7392-455A-8A1F-64935CB8B6ED}
BHO: C:\Program Files\BarreConfCMCIC\TAPBar.dll
C:\Program Files\BarreConfCMCIC\TAPBar.dll
225280 bytes
Created: 14/09/2007
Modified: 14/09/2007
Company: Euro-Information
----------
Key: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}
BHO: C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
368640 bytes
Created: 10/07/2008
Modified: 21/02/2005
Company: SEIKO EPSON CORPORATION
----------
Key: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
BHO: C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
160496 bytes
Created: 28/07/2008
Modified: 28/07/2008
Company: Yahoo! Inc
----------
************************************************************
19:53:31: Scanning ----- SHELLSERVICEOBJECTS -----
Key: WPDShServiceObj
CLSID: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}
Path: C:\WINDOWS\system32\WPDShServiceObj.dll
C:\WINDOWS\system32\WPDShServiceObj.dll
133632 bytes
Created: 18/10/2006
Modified: 18/10/2006
Company: Microsoft Corporation
----------
************************************************************
19:53:31: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
************************************************************
19:53:31: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
************************************************************
19:53:31: Scanning ----- APPINIT_DLLS -----
The AppInit_DLLs value is blank
************************************************************
19:53:32: Scanning ----- SECURITY PROVIDER DLLS -----
************************************************************
19:53:32: Scanning ------ COMMON STARTUP GROUP ------
[C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
-HS- 84 bytes
Created: 09/06/2008
Modified: 09/06/2008
Company:
--------------------
************************************************************
No User Startup Groups were located to check
************************************************************
19:53:32: Scanning ----- SCHEDULED TASKS -----
Taskname: AppleSoftwareUpdate.job
File: C:\Program Files\Apple Software Update\SoftwareUpdate.exe
C:\Program Files\Apple Software Update\SoftwareUpdate.exe
566592 bytes
Created: 30/07/2008
Modified: 30/07/2008
Company: Apple Inc.
Parameters: -task
Next Run Time: 13/09/2008 08:35:00
Status: La tâche n'a pas encore été exécutée
Creator: SYSTEM
Comments: [blank]
----------
************************************************************
19:53:32: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----
Key: Groove Explorer Icon Overlay 1 (GFS Unread Stub)
CLSID: {99FD978C-D287-4F50-827F-B2C658EDA8E7}
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
Key: Groove Explorer Icon Overlay 2 (GFS Stub)
CLSID: {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
Key: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)
CLSID: {920E6DB1-9907-4370-B3A0-BAFC03D81399}
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
Key: Groove Explorer Icon Overlay 3 (GFS Folder)
CLSID: {16F3DD56-1AF5-4347-846D-7C10C4192619}
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
Key: Groove Explorer Icon Overlay 4 (GFS Unread Mark)
CLSID: {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
File: C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL - file already scanned
----------
************************************************************
19:53:33: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Winlogon registry rootkit checks completed
----------
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: C:\Documents and Settings\Nina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
C:\Documents and Settings\Nina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
434046 bytes
Created: 10/07/2008
Modified: 28/07/2008
Company:
----------
Web Desktop Wallpaper: %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
C:\Documents and Settings\Nina\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
434046 bytes
Created: 10/07/2008
Modified: 28/07/2008
Company:
----------
Additional checks completed
************************************************************
19:53:34: Scanning ----- RUNNING PROCESSES -----
C:\WINDOWS\System32\smss.exe
--------------------
C:\WINDOWS\system32\csrss.exe
--------------------
C:\WINDOWS\system32\winlogon.exe
--------------------
C:\WINDOWS\system32\services.exe
--------------------
C:\WINDOWS\system32\lsass.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
--------------------
C:\Program Files\Alwil Software\Avast4\ashServ.exe
--------------------
C:\WINDOWS\system32\spoolsv.exe
--------------------
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
--------------------
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
--------------------
C:\WINDOWS\System32\alg.exe
--------------------
C:\WINDOWS\Explorer.EXE
--------------------
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
--------------------
C:\WINDOWS\SOUNDMAN.EXE
--------------------
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
--------------------
C:\Program Files\Apoint2K\Apoint.exe
--------------------
C:\WINDOWS\system32\khooker.exe
--------------------
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
--------------------
C:\Program Files\iTunes\iTunesHelper.exe
--------------------
C:\WINDOWS\system32\ctfmon.exe
--------------------
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
--------------------
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
--------------------
C:\Program Files\Apoint2K\Apntex.exe
--------------------
C:\Program Files\iPod\bin\iPodService.exe
--------------------
C:\Program Files\Windows Live\Messenger\usnsvc.exe
--------------------
C:\Program Files\Internet Explorer\IEXPLORE.EXE
--------------------
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
--------------------
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
--------------------
C:\Documents and Settings\Nina\Application Data\Simply Super Software\Trojan Remover\alg129.exe
FileSize: 2548288
[This is a Trojan Remover component]
--------------------
--------------------
************************************************************
19:53:36: Checking AUTOEXEC.BAT file
AUTOEXEC.BAT found in C:\
No malicious entries were found in the AUTOEXEC.BAT file
************************************************************
19:53:36: Checking AUTOEXEC.NT file
AUTOEXEC.NT found in C:\WINDOWS\system32
No malicious entries were found in the AUTOEXEC.NT file
************************************************************
19:53:36: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.01net.com/telecharger/
HKLM\Software\Microsoft\Internet Explorer\Main\"Local Page":
%SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://www.01net.com/telecharger/
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.google.fr/
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://www.01net.com/telecharger/
************************************************************
=== CHANGES WERE MADE TO THE WINDOWS REGISTRY ===
Scan completed at: 19:53:36 12 sept. 2008
Total Scan time: 00:00:45
-------------------------------------------------------------------------
One or more files could not be moved or renamed as requested.
They may be in use by Windows, so Trojan Remover needs
to restart the system in order to deal with these files.
12/09/2008 19:53:44: restart commenced
************************************************************