Virus_ Avis d'expert nécessaire

Résolu/Fermé
am13 - 12 déc. 2008 à 06:02
 am13 - 15 déc. 2008 à 12:27
Bonjour,
J'ai des problèmes de virus et autres spyware résistants. J'aurais voulu le conseil d'experts pour m'en débarrasser.
MERCIS !!
AM sur XP / IE & Mozilla

Voici dans l'ordre les résultats de la procédure proposée sur ce site :

---------------------------------------------------------------------------------------------------------------------------------------------------
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Scanned File


Status

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe


Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe


Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe


Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe


Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe


Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe


Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe


Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe


Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe


Detected with: Application.P2p.Networking.D

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe


Deleted

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe


Detected with: Adware.PlayMp3z.B

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe


Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe


Deleted

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip


Updated

C:\Program Files\Kazaa\CKGFRs.dll


Detected with: Application.Generic.18283

C:\Program Files\Kazaa\CKGFRs.dll


Disinfection failed

C:\Program Files\Kazaa\CKGFRs.dll


Deleted

C:\Program Files\Kazaa\TopSearch.dll


Detected with: Adware.Altnet.F

C:\Program Files\Kazaa\TopSearch.dll


Deleted

C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll


Detected with: Adware.Toolbar.Mywebsearch.O

C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>serial.exe


Infected with: Trojan.Generic.1222208

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>serial.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)


Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe


Infected with: Trojan.Vundo.GBQ

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)


Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe


Infected with: Trojan.Retapu.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)


Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027490.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027490.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL


Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027501.dll


Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027501.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027502.dll


Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027502.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027514.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027514.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027516.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027516.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027518.dll


Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027518.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL


Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027520.dll


Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027520.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027559.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027559.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027561.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027561.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027785.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027785.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027809.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027809.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027815.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027815.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027827.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027827.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027833.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027833.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027836.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027836.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL


Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027839.dll


Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027839.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027841.exe


Detected with: Adware.Topsearch.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027841.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027842.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027842.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027844.exe


Infected with: Trojan.Generic.1215518

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027844.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027845.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027845.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027846.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027846.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027847.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027847.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027928.dll


Detected with: Adware.Generic.30220

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027928.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027933.dll


Detected with: Adware.Altnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027933.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027934.dll


Detected with: Adware.Altnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027934.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027935.exe


Detected with: Adware.Altnet.Q

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027935.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027936.dll


Detected with: Adware.Altnet.F

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027936.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027937.dll


Detected with: Adware.Brilliantdigital.3039.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027937.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027938.dll


Detected with: Adware.Altnet.J

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027938.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027939.dll


Detected with: Adware.Altnetbde.B

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027939.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe


Detected with: Application.Altnetbde.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe


Detected with: Application.Altnetbde.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027963.DLL


Detected with: Adware.Msearch.M

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027963.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027964.DLL


Detected with: Adware.Toolbar.Mywebsearch.O

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027964.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0028026.dll


Detected with: Adware.Rxbar.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0028026.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0028164.dll


Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0028164.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029196.dll


Infected with: Trojan.Vundo.GBZ

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029196.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029197.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029197.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029198.exe


Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029198.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll


Infected with: Trojan.Vundo.FUX

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL


Detected with: Application.P2p.Networking.G

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029552.cpl


Detected with: Adware.P2pnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029552.cpl


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe


Detected with: Application.P2p.Networking.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll


Detected with: Application.Generic.18283

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll


Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032622.dll


Detected with: Adware.Altnet.F

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032622.dll


Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032623.dll


Detected with: Adware.Toolbar.Mywebsearch.O

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032623.dll


Deleted

C:\WINDOWS\cdmxtras\uninst.exe


Detected with: Application.Generic.23543

C:\WINDOWS\cdmxtras\uninst.exe


Disinfection failed

C:\WINDOWS\cdmxtras\uninst.exe


Deleted
--------------------------------------------------------------------------------------------------------------------------------------------------------------

BitDefender Online Scanner - Real Time Virus Report

Generated at: Fri, Dec 12, 2008 - 04:54:02

Scan Info

Scanned Files 218798

Infected Files 62




Virus Detected

Application.Generic.23543
1

Application.P2p.Networking.G
1

Application.Need2find.A
3

Trojan.Vundo.GBQ
1

Adware.PlayMp3z.B
1

Adware.Rxbar.D
1

Adware.Altnet.Q
1

Application.Generic.18283
2

Adware.Altnet.A
2

Adware.Generic.31649
3

Trojan.Vundo.FUX
1

Application.Altnetbde.A
1

Adware.Brilliantdigital.3039.C
1

Adware.P2pnet.A
1

Trojan.Generic.1215518
1

Application.Altnetbde.C
1

Adware.Topsearch.C
1

Worm.Generic.37658
17

Adware.Altnet.F
3

Trojan.Generic.1222208
1

Trojan.Vundo.GBZ
1

Adware.Generic.30220
1

Adware.RXToolbar
3

Adware.Msearch.M
1

Adware.Toolbar.Mywebsearch.O
3

Adware.Altnet.J
1

Packer.Malware.Lighty.E
4

Adware.Altnetbde.B
1

Application.P2p.Networking.D
2

Trojan.Retapu.D
1


--------------------------------------------------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:19:08, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://ange-live.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: itneuw.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll xvqehz.dll
O20 - Winlogon Notify: iifcDwxW - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

26 réponses

Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 06:32
Salut,

---> Télécharge Toolbar S&D (Team IDN) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0
Slt,
Merci pour ton aide voici le rapport :


-----------\\ ToolBar S&D 1.2.6 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 1.90GHz )
BIOS : BIOS Date: 05/22/02 16:06:01 Ver: 08.00.00
USER : amg ( Administrator )
BOOT : Normal boot
Antivirus : Kaspersky Anti-Virus 8.0.0.357 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:18 Go (Free:2 Go)
D:\ (CD or DVD)
E:\ (Local Disk) - NTFS - Total:97 Go (Free:48 Go)
F:\ (Local Disk) - NTFS - Total:30 Go (Free:20 Go)

"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [1] ( 12/12/2008| 6:58 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\WINDOWS\Prefetch\INSTAFINDER.EXE-25FCFB40.pf
C:\Program Files\KaZaA
C:\Program Files\KaZaA\ammp3.dll
C:\Program Files\KaZaA\bdupd.dll
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\Help
C:\Program Files\KaZaA\kazaa.exe
C:\Program Files\KaZaA\Kazaa.url
C:\Program Files\KaZaA\kzscan.dll
C:\Program Files\KaZaA\libcurl.dll
C:\Program Files\KaZaA\libeay32.dll
C:\Program Files\KaZaA\libssl32.dll
C:\Program Files\KaZaA\My Channels
C:\Program Files\KaZaA\My Search Agents
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\My Unshared Folder
C:\Program Files\KaZaA\myshare.ico
C:\Program Files\KaZaA\Skins
C:\Program Files\KaZaA\ssleay32.dll
C:\Program Files\KaZaA\BGP2P\bdcore.dll
C:\Program Files\KaZaA\BGP2P\libfn.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\Db\config.cab
C:\Program Files\KaZaA\Db\d01.cab
C:\Program Files\KaZaA\Db\d02.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Help\arrow.gif
C:\Program Files\KaZaA\Help\arrow_sml.gif
C:\Program Files\KaZaA\Help\background.gif
C:\Program Files\KaZaA\Help\h_mykazaa.gif
C:\Program Files\KaZaA\Help\h_myMedia.gif
C:\Program Files\KaZaA\Help\h_myplaylists.gif
C:\Program Files\KaZaA\Help\icon_gold_kap.gif
C:\Program Files\KaZaA\Help\myKapsules.gif
C:\Program Files\KaZaA\Help\mykapsules.htm
C:\Program Files\KaZaA\Help\mykazaa.css
C:\Program Files\KaZaA\Help\mykazaa.htm
C:\Program Files\KaZaA\Help\mymedia.htm
C:\Program Files\KaZaA\Help\myplaylists.htm
C:\Program Files\KaZaA\Help\spacer.gif
C:\Program Files\KaZaA\My Channels\Bin
C:\Program Files\KaZaA\My Channels\Images
C:\Program Files\KaZaA\My Channels\Bin\crazyplaygames.kcd
C:\Program Files\KaZaA\My Channels\Bin\dating.kcd
C:\Program Files\KaZaA\My Channels\Bin\emerging_artists.kcd
C:\Program Files\KaZaA\My Channels\Bin\g_spot.kcd
C:\Program Files\KaZaA\My Channels\Bin\onelove_browse.kcd
C:\Program Files\KaZaA\My Channels\Bin\ringtonechannel.kcd
C:\Program Files\KaZaA\My Channels\Bin\rshiphop.kcd
C:\Program Files\KaZaA\My Channels\Bin\skilledgames.kcd
C:\Program Files\KaZaA\My Channels\Images\crazyplaygames.bmp
C:\Program Files\KaZaA\My Channels\Images\dating.bmp
C:\Program Files\KaZaA\My Channels\Images\emerging_artists.bmp
C:\Program Files\KaZaA\My Channels\Images\g_spot.bmp
C:\Program Files\KaZaA\My Channels\Images\onelove_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\ringtonechannel.bmp
C:\Program Files\KaZaA\My Channels\Images\rshiphop_browse.bmp
C:\Program Files\KaZaA\My Channels\Images\skilledgames.bmp
C:\Program Files\KaZaA\My Shared Folder\Audio - Alternative Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Barrington Levy.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Electronica.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Fine Arts Militia Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Folk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Funk.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Hip Hop.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Jazz.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Pop Rock.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Public Enemy Revolverlution Album.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - R&B.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - Reggae.kpl
C:\Program Files\KaZaA\My Shared Folder\Audio - The Honey Palace Album.kpl
C:\Program Files\KaZaA\Skins\Black Glass
C:\Program Files\KaZaA\Skins\Black Glass\License.txt
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_mykazaa.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_mykazaa_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_mykazaa_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_mykazaa_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_peer.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_peer_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_peer_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_peer_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_search.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_search_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_search_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_search_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_shop.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_shop_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_shop_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_shop_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_start.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_start_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_start_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_start_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_tell.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_tell_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_tell_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_tell_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_theatre.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_theatre_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_theatre_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_theatre_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_traffic.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_traffic_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_traffic_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mainbar_traffic_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_addtoplay.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_addtoplay_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_addtoplay_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_addtoplay_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_next.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_next_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_next_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_next_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_pause.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_play.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_play_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_play_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_play_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_prev.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_prev_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_prev_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_prev_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_slider.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_sliderThumb.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_sliderThumb_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_stop.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_volume.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_volume_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_volume_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mediabar_volume_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_delete.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_delete_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_delete_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_delete_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_folders.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_folders_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_folders_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_folders_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_moreinfo.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_moreinfo_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_moreinfo_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_moreinfo_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_share.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_share_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_share_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\mykazaabar_share_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_closetabs.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_closetabs_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_closetabs_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_closetabs_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_download.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_download_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_download_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_download_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_messageuser.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_messageuser_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_messageuser_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_messageuser_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_newsearch.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_newsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_newsearch_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_newsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_searchuser.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_searchuser_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_searchuser_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_searchuser_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_showsearch.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_showsearch_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_showsearch_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\searchbar_showsearch_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\skin.xml
C:\Program Files\KaZaA\Skins\Black Glass\startbar_back.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_back_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_back_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_back_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_fwd.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_fwd_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_fwd_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_fwd_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_home.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_home_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_home_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_home_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_refresh.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_refresh_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_refresh_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_refresh_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_stop.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_stop_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_stop_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\startbar_stop_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\theatrebar_fullscreen.bmp
C:\Program Files\KaZaA\Skins\Black Glass\theatrebar_fullscreen_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\theatrebar_fullscreen_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\theatrebar_fullscreen_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_cancel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_cancel_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_cancel_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_cancel_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_pause.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_pause_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_pause_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_pause_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_resume.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_resume_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_resume_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\trafficbar_resume_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_close.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_close_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_close_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_close_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_maximise.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_maximise_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_maximise_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_maximise_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_minimise.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_minimise_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_minimise_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_minimise_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_restore.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_restore_dis.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_restore_over.bmp
C:\Program Files\KaZaA\Skins\Black Glass\windowbar_restore_sel.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_btm.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_btmLeft.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_btmright.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_left.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_right.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_top.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_topleft.bmp
C:\Program Files\KaZaA\Skins\Black Glass\window_topright.bmp
C:\DOCUME~1\AMG~1.ORD\Bureau\Kazaa.lnk
C:\DOCUME~1\AMG~1.ORD\MENUDM~1\PROGRA~1\Kazaa
C:\WINDOWS\Prefetch\P2P NETWORKING.EXE-2D369395.pf

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Bar"="http://www.bing.com/spresults.aspx"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 12/12/2008| 7:12 - Option : [1]

-----------\\ Fin du rapport a 7:12:11,48
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 07:21
---> Relance ToolBar S&D, fais l'option 2 et poste le rapport.
0
et hop !


-----------\\ ToolBar S&D 1.2.6 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 1.90GHz )
BIOS : BIOS Date: 05/22/02 16:06:01 Ver: 08.00.00
USER : amg ( Administrator )
BOOT : Normal boot
Antivirus : Kaspersky Anti-Virus 8.0.0.357 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:18 Go (Free:2 Go)
D:\ (CD or DVD)
E:\ (Local Disk) - NTFS - Total:97 Go (Free:48 Go)
F:\ (Local Disk) - NTFS - Total:30 Go (Free:20 Go)

"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [2] ( 12/12/2008| 7:24 )

-----------\\ SUPPRESSION

Supprime! - C:\WINDOWS\Prefetch\INSTAFINDER.EXE-25FCFB40.pf
Supprime! - C:\Program Files\KaZaA\ammp3.dll
Supprime! - C:\Program Files\KaZaA\bdupd.dll
Supprime! - C:\Program Files\KaZaA\BGP2P
Supprime! - C:\Program Files\KaZaA\Db
Supprime! - C:\Program Files\KaZaA\Help
Supprime! - C:\Program Files\KaZaA\kazaa.exe
Supprime! - C:\Program Files\KaZaA\Kazaa.url
Supprime! - C:\Program Files\KaZaA\kzscan.dll
Supprime! - C:\Program Files\KaZaA\libcurl.dll
Supprime! - C:\Program Files\KaZaA\libeay32.dll
Supprime! - C:\Program Files\KaZaA\libssl32.dll
Supprime! - C:\Program Files\KaZaA\My Channels
Supprime! - C:\Program Files\KaZaA\My Search Agents
Supprime! - C:\Program Files\KaZaA\My Shared Folder
Supprime! - C:\Program Files\KaZaA\My Unshared Folder
Supprime! - C:\Program Files\KaZaA\myshare.ico
Supprime! - C:\Program Files\KaZaA\Skins
Supprime! - C:\Program Files\KaZaA\ssleay32.dll
Supprime! - C:\DOCUME~1\AMG~1.ORD\Bureau\Kazaa.lnk
Supprime! - C:\DOCUME~1\AMG~1.ORD\MENUDM~1\PROGRA~1\Kazaa
Supprime! - C:\WINDOWS\Prefetch\P2P NETWORKING.EXE-2D369395.pf
Supprime! - C:\Program Files\KaZaA

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Bar"="http://www.bing.com/spresults.aspx"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 12/12/2008| 7:12 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 12/12/2008| 7:30 - Option : [2]

-----------\\ Fin du rapport a 7:30:30,95
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 08:09
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

- Double-clique sur RSIT.exe afin de lancer le programme.

- Clique sur Continue à l'écran Disclaimer.

- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
0
Logfile of random's system information tool 1.04 (written by random/random)
Run by amg at 2008-12-12 10:05:21
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 2 GB (11%) free of 19 GB
Total RAM: 255 MB (19% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:45, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\amg.ORDIAMG\Bureau\RSIT.exe
C:\Hijack this\amg.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://ange-live.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: itneuw.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll xvqehz.dll
O20 - Winlogon Notify: iifcDwxW - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 16:09
--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

--> Lance l'installation avec les paramètres par défaut.

--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

--> Double-clique sur le raccourci UsbFix sur ton Bureau.

--> Choisis l'option 1 (Nettoyage).

--> Le PC va redémarrer.

--> Après redémarrage, poste le rapport UsbFix.txt

Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
0
-------------- UsbFix V2.413.4 ---------------

* User : amg - ORDIAMG
* Outils mis a jours le 11/12/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 17:20:48 le 12/12/2008
* Windows Xp - Internet Explorer 7.0.5730.13


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\3.tmp\b2e.exe
C:\Program Files\QuickTime\qttask.exe

--------------- [ Informations lecteurs ] ----------------

C: - Lecteur fixe

E: - Lecteur fixe

F: - Lecteur fixe

G: - Lecteur amovible


--------------- [ Lecteur C ] ----------------

C: - Lecteur fixe


+- Listing des fichiers présents :

[09/05/2006 15:03][--a------] C:\AUTOEXEC.BAT
[04/02/2007 02:57][-rahs----] C:\NTDETECT.COM
[04/02/2007 03:12][-rahs----] C:\boot.ini
[12/12/2008 07:30][--a------] C:\TB.txt
[12/12/2008 07:30][--a------] C:\UsbFix.txt
[09/05/2006 15:03][--a------] C:\CONFIG.SYS
[09/05/2006 15:03][--a------] C:\hiberfil.sys
[09/05/2006 15:03][--a------] C:\IO.SYS
[09/05/2006 15:03][--a------] C:\MSDOS.SYS
[09/05/2006 15:03][--a------] C:\pagefile.sys

--------------- [ Lecteur E ] ----------------

E: - Lecteur fixe


+- Listing des fichiers présents :


--------------- [ Lecteur F ] ----------------

F: - Lecteur fixe


+- Listing des fichiers présents :


--------------- [ Lecteur G ] ----------------

G: - Lecteur amovible


+- Listing des fichiers présents :


--------------- [ Registre / Startup ] ----------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="c:\\windows\\system32\\userinit.exe,"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
updateMgr="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
SUPERAntiSpyware=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
Monitor=C:\WINDOWS\Philips\SPC220NC\Monitor.exe
HP Software Update=E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
AVP="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
!AVG Anti-Spyware="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

--------------- [ Registre / Mountpoint2 ] ----------------

Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec93f981-141d-11dc-8fe0-0050bfd76543}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ec93f981-141d-11dc-8fe0-0050bfd76543}\Shell\open\Command

--------------- [ Nettoyage des disques ] ----------------

Supprimé ! - [03/01/2008 15:10][--a------] C:\WINDOWS\system32\autorun.inf

--------------- [ Resumé ] ----------------

-> /!\ Le resultat doit etre interprété par un spécialiste /!\

[09/05/2006 15:03][--a------] C:\AUTOEXEC.BAT
[04/02/2007 02:57][-rahs----] C:\NTDETECT.COM
[04/02/2007 03:12][-rahs----] C:\boot.ini

--------------- ! Fin du rapport ! ----------------
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 17:37
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:files
C:\WINDOWS\cdmxtras
C:\WINDOWS\system32\c73de5c4-.txt

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifcDwxW]

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]





---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
Avant de démarrer j'ai une fenêtre de lancement de l'appli où il faut choisir un logiciel ??
Je n'accède pas aux items
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 17:50
Tu parles de quoi ?
0
je n'arrive pas à l'installer....
lors du lancement une fenêtre s'ouvre me demandant de choisir une application pour l'ouverture du fichier.
Si je fais annuler et que je x2 click sur l'icone du buro = erreur win32
Si je reclick sur le lien que tu m'as envoyé = erreur 404
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 18:11
Désactive ton antivirus sinon tu ne pourras pas télécharger OTMoveIt.
0
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\cdmxtras moved successfully.
C:\WINDOWS\system32\c73de5c4-.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifcDwxW\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_sL0blyzLdlirwVAMgVZS scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DFB2C3.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12122008_181912

Files moved on Reboot...
File C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_sL0blyzLdlirwVAMgVZS not found!
C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DFB2C3.tmp moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite moved successfully.
0
J'ai rafraichis mon cache et maintenant c'est kapersky qui s'en mêle......
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 18:31
---> Désinstalle UsbFix.

● Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

/!\ Déconnecte-toi et ferme toutes applications en cours /!\

● Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
● Double-clique sur l'icône Ad-remover située sur ton Bureau.
● Au menu principal, choisis l'option "A".
● Poste le rapport qui apparaît à la fin.

(Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

Note :

"Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
--------- Logfile of AD-Remover 1.0.7.5 by C_XX ---------

# START at: 18:41:50 | Ven 12/12/2008 | Microsoft® Windows XP™ (v5.1.2600)
# BOOT MODE: Normal

# OPTION: Scan | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat

# PC: ORDIAMG | USER: amg ( Current user is an administrator)

# DRIVE(S):
- C:\ (File System: NTFS)
- E:\ (File System: NTFS)
- F:\ (File System: NTFS)

# Internet Explorer v7.0.5730.13

--------- [ RUNNING PROCESSES: 29 ] ---------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\ntvdm.exe

-----------------------------------


+-----------------------| Boonty/Boonty Games Elements found :

.

+-----------------------| Eorezo Elements found :

"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
.
[05/04/2008 15:21|d--------] C:\Documents and Settings\All Users.WINDOWS\MENUDM~1\PROGRA~1\EoRezo

+-----------------------| Everest Poker Elements found :

.

+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements found :

.

+-----------------------| Messenger Skinner Elements found :

.

+-----------------------| Sweetim Elements found :

"HKEY_CLASSES_ROOT\Typelib\{58906392-79C4-497C-ACC6-6942B59F1A08}"
"HKEY_CURRENT_USER\SOFTWARE\SWEETIE"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
.

+-----------------------| ADDED SCAN :



+---------- Scanning prefs.js ... ( # Mozilla User Preferences )

...\mhwz9r6f.default\prefs.js :

~~~~ Mozilla FireFox version 3.0.4 ~~~~

Start Page : "https://www.google.fr/?client=firefox-a&rls=org.mozilla:fr:official&gws_rd=ssl"

+----------+


+---------------------------------------------------------------------------+

+--[HKEY_CURRENT_USER\..\Run]

CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
updateMgr REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

+--[HKEY_LOCAL_MACHINE\..\Run]

QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Monitor REG_SZ C:\WINDOWS\Philips\SPC220NC\Monitor.exe
HP Software Update REG_SZ E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
AVP REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
!AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

+--[HKEY_USERS\.DEFAULT\..\Run]

CTFMON.EXE REG_SZ C:\WINDOWS\System32\CTFMON.EXE

+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]

Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]

Start Page : hxxp://fr.msn.com/

+---------------------------------------------------------------------------+

- "C:\AD-report-12.12.2008.log" (4982 octets)

[ END at: 18:43:00 | 12/12/2008 ] - [ Time elapsed: 69.3 seconds ]

+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 93 lines ]
+---------------------------------------------------------------------------+
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 18:48
/!\ Déconnecte-toi et ferme toutes applications en cours /!\

● Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

● Coche à l'écran de sélection :
http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG

Suppression Boonty/BoontyGames (Si trouvé)
Suppression Eorezo (Si trouvé)
Suppression Everest Poker (Si trouvé)
Suppression Funwebproduct/MyWay/MyWebsearch (Si trouvé)
Suppression Messenger Skinner (Si trouvé)
Suppression Sweetim (Si trouvé)

● Puis choisis S, le programme va travailler.

● Poste le rapport qui apparaît à la fin.

(Le rapport est sauvegardé aussi sous C:\Ad-report.log)

/!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
0
Juste une p'tite chose, je me suis aperçu que je n'avais pas désinstallé le logiciel usb.. avant la phase A, je l'ai fait qu'avant la phase B....faut il que je relance la manip adremove ??


--------- Logfile of AD-Remover 1.0.7.5 by C_XX ---------

*** Limited to ***

Boonty/BoontyGames
Eorezo
Everest Poker
Funwebproduct/MyWay/MyWebsearch
Messenger Skinner
Sweetim

******************

# START at: 19:06:32 | Ven 12/12/2008 | Microsoft® Windows XP™ (v5.1.2600)
# BOOT MODE: Normal

# OPTION: Clean | EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat

# PC: ORDIAMG | USER: amg ( Current user is an administrator)

# DRIVE(S):
- C:\ (File System: NTFS)
- E:\ (File System: NTFS)
- F:\ (File System: NTFS)

# Internet Explorer v7.0.5730.13

--------- [ RUNNING PROCESSES: 29 ] ---------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\ntvdm.exe

-----------------------------------

(!) ---- IE start pages reset

+-----------------------| Boonty/Boonty Games Elements Deleted :

.

+-----------------------| Eorezo Elements Deleted :

"HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"
"HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
"HKEY_CURRENT_USER\SOFTWARE\EoRezo"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
"HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
.
[05/04/2008 15:21|d--------] C:\Documents and Settings\All Users.WINDOWS\MENUDM~1\PROGRA~1\EoRezo

+-----------------------| Everest Poker Elements Deleted :

.

+-----------------------| FunWebProducts/MyWay/MyWebSearch/MyGlobalSearch Elements Deleted :

.

+-----------------------| Messenger Skinner Elements Deleted :

.

+-----------------------| Sweetim Elements Deleted :

"HKEY_CLASSES_ROOT\Typelib\{58906392-79C4-497C-ACC6-6942B59F1A08}"
"HKEY_CURRENT_USER\SOFTWARE\SWEETIE"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Upgradecodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}"
"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Macrogaming"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar" /v "{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9"
.

(!) ---- Temp files deleted.
(!) ---- Recycle bin emptied in all drives.


+-----------------------| ADDED SCAN :



+---------- Scanning prefs.js ... ( # Mozilla User Preferences )

...\mhwz9r6f.default\prefs.js :

~~~~ Mozilla FireFox version 3.0.4 ~~~~

Start Page : "https://www.google.fr/?client=firefox-a&rls=org.mozilla:fr:official&gws_rd=ssl"

+----------+

+--[HKEY_CURRENT_USER\..\Run]

CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
updateMgr REG_SZ "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

+--[HKEY_LOCAL_MACHINE\..\Run]

QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Monitor REG_SZ C:\WINDOWS\Philips\SPC220NC\Monitor.exe
HP Software Update REG_SZ E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
AVP REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
!AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

+--[HKEY_USERS\.DEFAULT\..\Run]

CTFMON.EXE REG_SZ C:\WINDOWS\System32\CTFMON.EXE

+--[HKEY_CURRENT_USER\..\Internet Explorer\MAIN]

Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

+--[HKEY_LOCAL_MACHINE\..\Internet Explorer\MAIN]

Start Page : hxxp://fr.msn.com/

+---------------------------------------------------------------------------+

- "C:\AD-report-12.12.2008.log" (5172 octets)

[ END at: 19:11:24 | 12/12/2008 ] - [ Time elapsed: 4 minutes, 52 seconds ]

+---------------------------------------------------------------------------+
+------------------------------- [ E.O.F - 103 lines ]
+---------------------------------------------------------------------------+
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 19:18
Sans soucis pour UsbFix.

---> Désinstalle AD-Remover.

---> Supprime le dossier RSIT situé dans C:\

---> Refais un scan RSIT et poste les deux rapports.
0
Logfile of random's system information tool 1.04 (written by random/random)
Run by amg at 2008-12-12 19:23:24
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 2 GB (13%) free of 19 GB
Total RAM: 255 MB (21% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:23:43, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\amg.ORDIAMG\Bureau\RSIT.exe
C:\Hijack this\amg.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://ange-live.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: itneuw.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll xvqehz.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 20:03
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]





---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll /E :invalid edit format. Invalid data type.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_ZTljgduHdXP4dS8blMms scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DF5804.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12122008_200842

Files moved on Reboot...
File C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_ZTljgduHdXP4dS8blMms not found!
C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DF5804.tmp moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite moved successfully.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 20:34
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=""

:commands
[purity]
[emptytemp]
[start explorer]
[reboot]





---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_YJor7RbIuQoXBDM4yaGN scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DF5874.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12122008_204222

Files moved on Reboot...
File C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\etilqs_YJor7RbIuQoXBDM4yaGN not found!
C:\DOCUME~1\AMG~1.ORD\LOCALS~1\Temp\~DF5874.tmp moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\amg.ORDIAMG\Local Settings\Application Data\Mozilla\Firefox\Profiles\mhwz9r6f.default\XUL.mfl moved successfully.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 20:50
Réinstalle Kaspersky.
0
Je désinstalle et réinstalle ?? ou juste je relance ?!
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 21:07
Réinstalle.
0
ok! je scanne..
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
12 déc. 2008 à 23:14
Ok.
0
Bonjour,
Voici donc l'analyse du scan :
supprimé : cheval de Troie Backdoor.Win32.SubSeven.asu Le fichier: C:\Documents and Settings\amg.ORDIAMG\Bureau\OTMoveIt3.exe
supprimé : logiciel publicitaire not-a-virus:AdWare.Win32.Altnet.d Le fichier: C:\ToolBar SD\Backup-TB\Program Files\Kazaa\kazaa.exe//Execryptor/TopSearch.dll

Est-ce que mon ordi est guéri ??
; )
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
13 déc. 2008 à 09:23
---> Mets à jour Adobe Reader :
https://get2.adobe.com/reader/otherversions/

---> Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries sur ton Bureau :
* Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Clique sur Search For Updates.
* Sélectionne Update Using jucheck.exe puis clique sur Search.
* Autorise le processus à se connecter s'il le demande, clique sur Install et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Remove Older Versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur Ok, puis une deuxième fois sur Ok.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

---> Supprime le dossier RSIT situé dans C:\

---> Refais un scan RSIT et poste les deux rapports.
0
JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Sat Dec 13 15:21:13 2008

Found and removed: C:\Program Files\Java\jre1.6.0_02

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\JavaPlugin.160_02

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610002

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160020}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: Software\Classes\JavaPlugin.160_02

Found and removed: Software\Classes\JavaPlugin.160_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_02

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.






Logfile of random's system information tool 1.04 (written by random/random)
Run by amg at 2008-12-13 15:25:01
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 1 GB (8%) free of 19 GB
Total RAM: 255 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:25:19, on 13/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\wscntfy.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\amg.ORDIAMG\Bureau\RSIT.exe
C:\Hijack this\amg.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - E:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - E:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://ange-live.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
0
info.txt logfile of random's system information tool 1.04 2008-12-13 15:25:37

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Apple Software Update-->MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Barre d'outils MSN-->C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\mtbs.exe c
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Google Earth-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x40c -removeonly
HijackThis 2.0.2-->"C:\Hijack this\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
HP Customer Participation Program 9.0-->E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 9.0-->E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OCR Software 9.0-->E:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP Photosmart All-In-One Software 9.0-->E:\Program Files\HP\Digital Imaging\{B09BCBF6-87EE-4403-A336-3A9510856535}\setup\hpzscr01.exe -datfile hposcr15.dat
HP Photosmart Essential 2.01-->E:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0-->E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
iTunes-->MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Kaspersky Anti-Virus 7.0-->MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Kaspersky Anti-Virus 7.0-->MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Kazaa 3.2.7-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EC8923CA-D7F5-46E4-98BB-E083E6E1C40D}\Setup.exe" -l0x9 --AddRemove
K-Lite Codec Pack 3.8.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
LimeWire 4.18.6-->"C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB925454)-->"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931768)-->"C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB933566)-->"C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB942615)-->"C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944338)-->"C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944533)-->"C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB947864)-->"C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB942840)-->"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB946627)-->"C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
Philips SPC220NC Webcam-->C:\Program Files\InstallShield Installation Information\{97CB5A86-4887-4919-A251-FBF6414A200D}\setup.exe -runfromtemp -l0x040c -removeonly
QuickTime-->MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
SAMSUNG PC Studio 2.0.9-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{D48C9BFC-FBCF-4F29-B97D-822ED6D497FE}
Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
Samsung USB Driver (MCCI 4.24)-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{77F09242-A107-4CB6-A295-D8656C2C3795}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
SweetIM For Internet Explorer 3.0b-->MsiExec.exe /X{F6D63A65-BD23-46F3-B9A3-87F442423481}
VideoLAN VLC media player 0.8.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Webcam Video Viewer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CECB7782-F35F-45CE-97C0-74BBBDC51C22}\Setup.exe" -l0x40c
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall

======Security center information======

AV: Kaspersky Anti-Virus (disabled)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 1 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=0102
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO

-----------------EOF-----------------
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 290
13 déc. 2008 à 17:38
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen complet.
---> Clique sur Rechercher. L'analyse démarre, le scan est relativement long, c'est normal.

A la fin de l'analyse, un message s'affiche :

L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
0
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1497
Windows 5.1.2600 Service Pack 2

13/12/2008 19:39:15
mbam-log-2008-12-13 (19-39-15).txt

Type de recherche: Examen complet (C:\|E:\|F:\|)
Eléments examinés: 124682
Temps écoulé: 1 hour(s), 52 minute(s), 20 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029207.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
0