-
Compteur de contenus
25 823 -
Inscription
-
Dernière visite
-
Jours gagnés
383
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par Apollo
-
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Bonjour BipBip, D'après Cécile, rien de tout cela à cet endroit mais je doute un peu, je vais donc lui redemander de bien regarder cela. Rapport HJT d'hier en attendant résultats Ewido et nouveau log HJT: Logfile of HijackThis v1.99.1 Scan saved at 16:17:01, on 13/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\System32\ELAN.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\GSICON.EXE C:\WINDOWS\System32\dslagent.exe C:\Program Files\D-Tools\daemon.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Shareaza\Shareaza.exe C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\palstart(2).exe C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\palstart.exe C:\WINDOWS\System32\NotifyPhoneBook.exe C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: phoneaccess Class - {5054F860-748D-4840-B7B4-DDDB428421AF} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [RemoveElanIcon] C:\WINDOWS\System32\ELAN.exe O4 - HKLM\..\Run: [AME_CSA] rundll32 AmeCSA.cpl,RUN_DLL O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008 O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [services32] C:\Program Files\Fichiers communs\Windows\mc-48-555-0000027.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - Startup: desktop(2)(2)(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(2)(3).ini O4 - Startup: desktop(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(3)(2).ini O4 - Startup: desktop(2)(2)(2)(3).ini O4 - Startup: desktop(2)(2)(2)(4).ini O4 - Startup: desktop(2)(2)(2).ini O4 - Startup: desktop(2)(2)(3)(2)(2).ini O4 - Startup: desktop(2)(2)(3)(2).ini O4 - Startup: desktop(2)(2)(3)(3).ini O4 - Startup: desktop(2)(2)(3).ini O4 - Startup: desktop(2)(2)(4)(2).ini O4 - Startup: desktop(2)(2)(4).ini O4 - Startup: desktop(2)(2)(5).ini O4 - Startup: desktop(2)(2).ini O4 - Startup: desktop(2)(3)(2)(2)(2).ini O4 - Startup: desktop(2)(3)(2)(2).ini O4 - Startup: desktop(2)(3)(2)(3).ini O4 - Startup: desktop(2)(3)(2).ini O4 - Startup: desktop(2)(3)(3)(2).ini O4 - Startup: desktop(2)(3)(3).ini O4 - Startup: desktop(2)(3)(4).ini O4 - Startup: desktop(2)(3).ini O4 - Startup: desktop(2)(4)(2)(2).ini O4 - Startup: desktop(2)(4)(2).ini O4 - Startup: desktop(2)(4)(3).ini O4 - Startup: desktop(2)(4).ini O4 - Startup: desktop(2)(5)(2).ini O4 - Startup: desktop(2)(5).ini O4 - Startup: desktop(2)(6).ini O4 - Startup: desktop(2).ini O4 - Startup: desktop(3)(2)(2)(2)(2).ini O4 - Startup: desktop(3)(2)(2)(2).ini O4 - Startup: desktop(3)(2)(2)(3).ini O4 - Startup: desktop(3)(2)(2).ini O4 - Startup: desktop(3)(2)(3)(2).ini O4 - Startup: desktop(3)(2)(3).ini O4 - Startup: desktop(3)(2)(4).ini O4 - Startup: desktop(3)(2).ini O4 - Startup: desktop(3)(3)(2)(2).ini O4 - Startup: desktop(3)(3)(2).ini O4 - Startup: desktop(3)(3)(3).ini O4 - Startup: desktop(3)(3).ini O4 - Startup: desktop(3)(4)(2).ini O4 - Startup: desktop(3)(4).ini O4 - Startup: desktop(3)(5).ini O4 - Startup: desktop(3).ini O4 - Startup: desktop(4)(2)(2)(2).ini O4 - Startup: desktop(4)(2)(2).ini O4 - Startup: desktop(4)(2)(3).ini O4 - Startup: desktop(4)(2).ini O4 - Startup: desktop(4)(3)(2).ini O4 - Startup: desktop(4)(3).ini O4 - Startup: desktop(4)(4).ini O4 - Startup: desktop(4).ini O4 - Startup: desktop(5)(2).ini O4 - Startup: desktop(5).ini O4 - Global Startup: desktop(2)(2)(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(3)(2).ini O4 - Global Startup: desktop(2)(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(2)(4).ini O4 - Global Startup: desktop(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(3)(2)(2).ini O4 - Global Startup: desktop(2)(2)(3)(2).ini O4 - Global Startup: desktop(2)(2)(3)(3).ini O4 - Global Startup: desktop(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(4)(2).ini O4 - Global Startup: desktop(2)(2)(4).ini O4 - Global Startup: desktop(2)(2)(5).ini O4 - Global Startup: desktop(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(3).ini O4 - Global Startup: desktop(2)(3)(2).ini O4 - Global Startup: desktop(2)(3)(3)(2).ini O4 - Global Startup: desktop(2)(3)(3).ini O4 - Global Startup: desktop(2)(3)(4).ini O4 - Global Startup: desktop(2)(3).ini O4 - Global Startup: desktop(2)(4)(2)(2).ini O4 - Global Startup: desktop(2)(4)(2).ini O4 - Global Startup: desktop(2)(4)(3).ini O4 - Global Startup: desktop(2)(4).ini O4 - Global Startup: desktop(2)(5)(2).ini O4 - Global Startup: desktop(2)(5).ini O4 - Global Startup: desktop(2)(6).ini O4 - Global Startup: desktop(2).ini O4 - Global Startup: desktop(3)(2)(2)(2)(2).ini O4 - Global Startup: desktop(3)(2)(2)(2).ini O4 - Global Startup: desktop(3)(2)(2)(3).ini O4 - Global Startup: desktop(3)(2)(2).ini O4 - Global Startup: desktop(3)(2)(3)(2).ini O4 - Global Startup: desktop(3)(2)(3).ini O4 - Global Startup: desktop(3)(2)(4).ini O4 - Global Startup: desktop(3)(2).ini O4 - Global Startup: desktop(3)(3)(2)(2).ini O4 - Global Startup: desktop(3)(3)(2).ini O4 - Global Startup: desktop(3)(3)(3).ini O4 - Global Startup: desktop(3)(3).ini O4 - Global Startup: desktop(3)(4)(2).ini O4 - Global Startup: desktop(3)(4).ini O4 - Global Startup: desktop(3)(5).ini O4 - Global Startup: desktop(3).ini O4 - Global Startup: desktop(4)(2)(2)(2).ini O4 - Global Startup: desktop(4)(2)(2).ini O4 - Global Startup: desktop(4)(2)(3).ini O4 - Global Startup: desktop(4)(2).ini O4 - Global Startup: desktop(4)(3)(2).ini O4 - Global Startup: desktop(4)(3).ini O4 - Global Startup: desktop(4)(4).ini O4 - Global Startup: desktop(4).ini O4 - Global Startup: desktop(5)(2)(2).ini O4 - Global Startup: desktop(5)(2).ini O4 - Global Startup: desktop(5)(3).ini O4 - Global Startup: desktop(5).ini O4 - Global Startup: desktop(6)(2).ini O4 - Global Startup: desktop(6).ini O4 - Global Startup: palstart(2).exe O4 - Global Startup: palstart.exe O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/eng/boards_2_0_0_21.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-30.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5054F860-748D-4840-B7B4-DDDB428421AF} (phoneaccess Class) - http://ip.sponsoradulto.com/cab/4/fr/phoneaccess.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1122920828967 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {701DC9DC-ACD5-4E94-85E3-F3F1ED68611A} (CWebClientCtl Object) - http://download.paltalk.com/webclient_prod...ebclientctl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {E9790C6C-DCAA-4E4F-8048-FFEC3B62DFED} (VOGWeb2 Class) - http://216.32.89.203/activex/vogweb29.cab O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...rcabinstall.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C2} (GameDesire Pool 9) - http://67.15.101.3/g_bin/eng/billard9_2_0_0_24.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: MAPI Mail Client (MAPI) - Unknown owner - C:\WINDOWS\System32\mapi32.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Je lui ai dit de virer son P2P déjà plusieurs fois... -
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Toujours là! Incident Status Location Adware:adware/maxifiles Not desinfected C:\PROGRAM FILES\FICHIERS COMMUNS\InetGet Adware:adware/exact.bargainbuddyNot desinfected Windows Registry Les instructions ont été suivies Charles, du moins c'est ce qui m'est certifié... -
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Re, Pendant ce temps j'ai eu le rapport Antivir: Creation date of the report file: mardi 13 décembre 2005 13:01 AntiVir®/XP (2000 + NT) PersonalEdition Classic Build 1114 of 04.11.2005 Mainprogram 6.32.00.51 of 03.11.2005 VDF file 6.33.0.20 (0) of 12.12.2005 This program is for PERSONAL USE only. Any other use is PROHIBITED. Informations regarding commercial versions of AntiVir may be obtained from: www.hbedv.com. Scanning for 262109 virus strains and unwanted programs. Licensed for: AntiVir Personal Edition Serial number: 0000149991-WURGE-0001 Please enter the workstation and contact name with phone number in this form: Name ___________________________________________ Street ___________________________________________ Town ___________________________________________ Phone/Fax ___________________________________________ Email ___________________________________________ Platform: Windows NT Workstation Windows version: 5.1 Build 2600 () Username: X Processor: Pentium Working memory: 1572076 KB free Version information: AVWIN.DLL : 6.32.00.51 561192 04.11.2005 07:50:54 AVEWIN32.DLL : 6.33.0.61 1004032 24.11.2005 17:53:20 AVGNT.EXE : 6.32.00.02 180327 03.11.2005 17:06:56 AVGUARD.EXE : 6.32.00.12 208424 03.11.2005 17:06:58 GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 10:24:12 AVGCMSG.DLL : 6.32.00.01 295029 03.11.2005 17:06:58 AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16 AVPACK32.DLL : 6.32.00.02 319528 03.11.2005 16:57:42 AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 17:10:20 AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 17:10:22 AVSched32.EXE : 6.32.00.01 110632 20.09.2005 14:16:26 AVSched32.DLL : 6.30.00.00 122880 01.02.2005 10:24:12 AVREG.DLL : 6.31.00.05 41000 07.09.2005 16:34:50 AVRep.DLL : 6.33.00.08 1577000 06.12.2005 11:09:16 INETUPD.EXE : 6.32.00.53 262203 04.11.2005 07:49:30 INETUPD.DLL : 6.32.00.53 143360 04.11.2005 07:49:30 CTL3D32.DLL : 2.31.000 27136 28.08.2001 13:00:00 MFC42.DLL : 6.00.8665.0 995383 28.08.2001 13:00:00 MSVCRT.DLL : 7.0.2600.0 (xpclient.010817-1148 MSVCRT.DLL : 7.0.2600.0 (xp 322560 28.08.2001 13:00:00 CTL3DV2.DLL : No information Configuration file: Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG Start path: C:\Program Files\AVPersonal Command line: Start mode: unknown Mode of report file: [ ] Do not create report [X] Overwrite report [ ] Append new report Data in report file: [X] Infected files [ ] Infected files with paths [ ] All scanned files [ ] Full information Abridge report file: [ ] Abridge report file Warnings in report: [X] Access denied/file locked [X] Wrong file size in directory [X] Wrong creation time in directory [ ] COM file is too large [X] Invalid start address [X] Invalid EXE header [X] Possibly damaged Summary report: [X] Create summary report Output file: AVWIN.ACT Maximum number of entries: 100 Where to search: [X] Memory [X] Boot record of selected drives [ ] Report unknown boot sectors [X] All files [ ] Program files Response in case of a detection: [X] Repair with prompt [ ] Repair without prompt [ ] Delete with prompt [ ] Delete without prompt [ ] Write in report file only [X] Acoustic alarm Response in case of destroyed files: [X] Delete with prompt [ ] Delete without prompt [ ] Ignore Response in case of destroyed files: [X] No change [ ] Current system time [ ] Correct date Drag&drop settings: [X] Scan subdirectories Profile settings: [X] Scan subdirectories Archive options [X] Search archive [X] Archive types to leave out 1002 1001 1000 Miscellaneous options: Temporary path: %TEMP% -> C:\DOCUME~1\X\LOCALS~1\Temp [X] Overwrite infected files [ ] Detect idle time [X] Allow interruptions of scan [ ] Load AVWin®/NT Guard on System start General settings: [X] Save options on exiting AntiVir Priority: medium Drives: A: Floppy drive C: Hard disk D: CD-ROM E: CD-ROM F: CD-ROM Start of scan: mardi 13 décembre 2005 13:01 Memory test OK Master boot record of hard disk HD0 OK Boot record of drive C: OK Access denied! Error during file opening! Error code: 0x0002 C:\ WARNING! Access error/file locked! C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery AlexaRelated.zip ArchiveType: ZIP NOTE! The whole archive is password protected ExactAdvertisingBargainsBuddy.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINDashBar.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINDashBar1.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINDashBar2.zip ArchiveType: ZIP GAINDashBar3.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINDashBar4.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINDashBar5.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator1.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator10.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator11.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator12.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator13.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator14.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator15.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator16.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator17.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator18.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator19.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator2.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator20.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator21.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator22.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator23.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator24.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator25.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator26.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator27.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator28.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator29.zip ArchiveType: ZIP GAINGator3.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator30.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator31.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator32.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator33.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator34.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator35.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator36.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator37.zip ArchiveType: ZIP GAINGator38.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator39.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator4.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator40.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator5.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator6.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator7.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator8.zip ArchiveType: ZIP NOTE! The whole archive is password protected GAINGator9.zip ArchiveType: ZIP NOTE! The whole archive is password protected Hotbar.zip ArchiveType: ZIP NOTE! The whole archive is password protected Hotbar1.zip ArchiveType: ZIP Hotbar2.zip ArchiveType: ZIP NOTE! The whole archive is password protected Hotbar3.zip ArchiveType: ZIP NOTE! The whole archive is password protected Hotbar4.zip ArchiveType: ZIP NOTE! The whole archive is password protected Hotbar5.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch1.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch10.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch11.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch12.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch13.zip ArchiveType: ZIP MaxSearch2.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch3.zip ArchiveType: ZIP MaxSearch4.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch5.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch6.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch7.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch8.zip ArchiveType: ZIP NOTE! The whole archive is password protected MaxSearch9.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMyBar.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch1.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch10.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch11.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch12.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch13.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch14.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch15.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch16.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch2.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch3.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch4.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch5.zip ArchiveType: ZIP MyWayMySearch6.zip ArchiveType: ZIP MyWayMySearch7.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch8.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWayMySearch9.zip ArchiveType: ZIP NOTE! The whole archive is password protected SolutionsSearchAssistant.zip ArchiveType: ZIP NOTE! The whole archive is password protected C:\Documents and Settings\mika\Local Settings\Temp\hsperfdata_mika 2248 Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\X ntuser.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\X\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Program Files\BoontyGames\Ricochet Lost World Recharged Data.dat ArchiveType: ZIP C:\Program Files\LimeWire\.NetworkShare nemo ps1.rar ArchiveType: RAR --> setup.exe [DETECTION] Is the Trojan horse TR/Dldr.IstBar.nj.1 nemo ps1.zip ArchiveType: ZIP --> setup.exe [DETECTION] Is the Trojan horse TR/Dldr.IstBar.nj.1 C:\Program Files\PC Wizard 2006\Web webupdt.exe [DETECTION] Contains suspicious code HEURISTIC/Trojan.Downloader WAS DELETED! C:\Program Files\Rockstar Games\GTA San Andreas pztrain.exe [DETECTION] Contains an unusual runtime compression tool (PCK/MEW). Please verify the origin of the file WAS DELETED! C:\Program Files\WinRAR rarnew.dat ArchiveType: RAR NOTE! The archive is created by multiple volumes C:\Program Files\Yahoo!\YPSR\Quarantine 20050927101448.zip ArchiveType: ZIP --> persist.dbs NOTE! The file is password protected --> LimeWirePackedJars4.9.23.7z NOTE! The file is password protected --> LimeWirePackedJars4.9.28.7z NOTE! The file is password protected --> LimeWirePackedJars4.9.30.7z NOTE! The file is password protected --> LimeWireWin4.9.23.exe NOTE! The file is password protected --> LimeWireWin4.9.28(2).exe NOTE! The file is password protected --> clink.jar NOTE! The file is password protected --> commons-httpclient.jar NOTE! The file is password protected --> commons-logging.jar NOTE! The file is password protected --> COPYING NOTE! The file is password protected --> daap.jar NOTE! The file is password protected --> data.ser NOTE! The file is password protected --> GenericWindowsUtils(2).dll NOTE! The file is password protected --> hashes NOTE! The file is password protected --> i18n.jar NOTE! The file is password protected --> icu4j.jar NOTE! The file is password protected --> id3v2.jar NOTE! The file is password protected --> install.log NOTE! The file is password protected --> jcraft.jar NOTE! The file is password protected --> jl011.jar NOTE! The file is password protected --> jmdns.jar NOTE! The file is password protected --> language.prop NOTE! The file is password protected --> LimeWire On Startup.lnk NOTE! The file is password protected --> LimeWire(2).exe NOTE! The file is password protected --> LimeWire(2).ico NOTE! The file is password protected --> LimeWire.exe NOTE! The file is password protected --> LimeWire.ico NOTE! The file is password protected --> LimeWire.jar NOTE! The file is password protected --> LimeWire20(2).dll NOTE! The file is password protected --> logicrypto.jar NOTE! The file is password protected --> looks.jar NOTE! The file is password protected --> MessagesBundle.properties NOTE! The file is password protected --> MessagesBundles.jar NOTE! The file is password protected --> mp3sp14.jar NOTE! The file is password protected --> pmf.ico NOTE! The file is password protected --> ProgressTabs.jar NOTE! The file is password protected --> badge.img NOTE! The file is password protected --> limewire.gif NOTE! The file is password protected --> options.js NOTE! The file is password protected --> silentdetect.js NOTE! The file is password protected --> badge.img NOTE! The file is password protected --> limewire.gif NOTE! The file is password protected --> options.js NOTE! The file is password protected --> silentdetect.js NOTE! The file is password protected --> SOURCE NOTE! The file is password protected --> spacer.gif NOTE! The file is password protected --> themes.jar NOTE! The file is password protected --> tritonus.jar NOTE! The file is password protected --> uninstall.exe NOTE! The file is password protected --> unpack.log NOTE! The file is password protected --> update.ver NOTE! The file is password protected --> vorbis.jar NOTE! The file is password protected --> WindowsV5PlusUtils(2).dll NOTE! The file is password protected --> xerces.jar NOTE! The file is password protected --> xml-apis.jar NOTE! The file is password protected --> xml.war NOTE! The file is password protected --> reg9E.tmp NOTE! The file is password protected --> x@2o7[1].txt NOTE! The file is password protected 20051110200250.zip ArchiveType: ZIP --> LimeWirePackedJars4.9.28.7z NOTE! The file is password protected --> LimeWirePackedJars4.9.30.7z NOTE! The file is password protected --> LimeWireWin4.9.28.exe NOTE! The file is password protected --> LimeWireWin4.9.30.exe NOTE! The file is password protected --> clink.jar NOTE! The file is password protected --> commons-httpclient.jar NOTE! The file is password protected --> commons-logging.jar NOTE! The file is password protected --> COPYING NOTE! The file is password protected --> daap.jar NOTE! The file is password protected --> data.ser NOTE! The file is password protected --> GenericWindowsUtils.dll NOTE! The file is password protected --> hashes NOTE! The file is password protected --> i18n.jar NOTE! The file is password protected --> icu4j.jar NOTE! The file is password protected --> id3v2.jar NOTE! The file is password protected --> install.log NOTE! The file is password protected --> jcraft.jar NOTE! The file is password protected --> jl011.jar NOTE! The file is password protected --> jmdns.jar NOTE! The file is password protected --> language.prop NOTE! The file is password protected --> LimeWire On Startup.lnk NOTE! The file is password protected --> LimeWire.exe NOTE! The file is password protected --> LimeWire.ico NOTE! The file is password protected --> LimeWire.jar NOTE! The file is password protected --> LimeWire20.dll NOTE! The file is password protected --> logicrypto.jar NOTE! The file is password protected --> looks.jar NOTE! The file is password protected --> MessagesBundle.properties NOTE! The file is password protected --> MessagesBundles.jar NOTE! The file is password protected --> mp3sp14.jar NOTE! The file is password protected --> pmf.ico NOTE! The file is password protected --> ProgressTabs.jar NOTE! The file is password protected --> badge.img NOTE! The file is password protected --> limewire.gif NOTE! The file is password protected --> options.js NOTE! The file is password protected --> silentdetect.js NOTE! The file is password protected --> SOURCE NOTE! The file is password protected --> spacer.gif NOTE! The file is password protected --> themes.jar NOTE! The file is password protected --> tritonus.jar NOTE! The file is password protected --> uninstall.exe NOTE! The file is password protected --> unpack.log NOTE! The file is password protected --> update.ver NOTE! The file is password protected --> vorbis.jar NOTE! The file is password protected --> WindowsV5PlusUtils.dll NOTE! The file is password protected --> xerces.jar NOTE! The file is password protected --> xml-apis.jar NOTE! The file is password protected --> xml.war NOTE! The file is password protected --> LimeWirePackedJars4.9.28.7z NOTE! The file is password protected --> LimeWirePackedJars4.9.30.7z NOTE! The file is password protected --> LimeWireWin4.9.28.exe NOTE! The file is password protected --> LimeWireWin4.9.30.exe NOTE! The file is password protected --> clink.jar NOTE! The file is password protected --> commons-httpclient.jar NOTE! The file is password protected --> commons-logging.jar NOTE! The file is password protected --> COPYING NOTE! The file is password protected --> daap.jar NOTE! The file is password protected --> data.ser NOTE! The file is password protected --> GenericWindowsUtils.dll NOTE! The file is password protected --> hashes NOTE! The file is password protected --> i18n.jar NOTE! The file is password protected --> icu4j.jar NOTE! The file is password protected --> id3v2.jar NOTE! The file is password protected --> install.log NOTE! The file is password protected --> jcraft.jar NOTE! The file is password protected --> jl011.jar NOTE! The file is password protected --> jmdns.jar NOTE! The file is password protected --> language.prop NOTE! The file is password protected --> LimeWire On Startup.lnk NOTE! The file is password protected --> LimeWire.exe NOTE! The file is password protected --> LimeWire.ico NOTE! The file is password protected --> LimeWire.jar NOTE! The file is password protected --> LimeWire20.dll NOTE! The file is password protected --> logicrypto.jar NOTE! The file is password protected --> looks.jar NOTE! The file is password protected --> MessagesBundle.properties NOTE! The file is password protected --> MessagesBundles.jar NOTE! The file is password protected --> mp3sp14.jar NOTE! The file is password protected --> pmf.ico NOTE! The file is password protected --> ProgressTabs.jar NOTE! The file is password protected --> badge.img NOTE! The file is password protected --> limewire.gif NOTE! The file is password protected --> options.js NOTE! The file is password protected --> silentdetect.js NOTE! The file is password protected --> SOURCE NOTE! The file is password protected --> spacer.gif NOTE! The file is password protected --> themes.jar NOTE! The file is password protected --> tritonus.jar NOTE! The file is password protected --> uninstall.exe NOTE! The file is password protected --> unpack.log NOTE! The file is password protected --> update.ver NOTE! The file is password protected --> vorbis.jar NOTE! The file is password protected --> WindowsV5PlusUtils.dll NOTE! The file is password protected --> xerces.jar NOTE! The file is password protected --> xml-apis.jar NOTE! The file is password protected --> xml.war NOTE! The file is password protected --> reg6F.tmp NOTE! The file is password protected --> x@bluestreak[2].txt NOTE! The file is password protected --> x@metriweb[1].txt NOTE! The file is password protected --> x@tradedoubler[2].txt NOTE! The file is password protected --> x@weborama[1].txt NOTE! The file is password protected --> clink.jar NOTE! The file is password protected --> commons-httpclient.jar NOTE! The file is password protected --> commons-logging.jar NOTE! The file is password protected --> daap.jar NOTE! The file is password protected --> GenericWindowsUtils.dll NOTE! The file is password protected --> i18n.jar NOTE! The file is password protected --> icu4j.jar NOTE! The file is password protected --> id3v2.jar NOTE! The file is password protected --> jcraft.jar NOTE! The file is password protected --> jl011.jar NOTE! The file is password protected --> jmdns.jar NOTE! The file is password protected --> LimeWire.exe NOTE! The file is password protected --> LimeWire.jar NOTE! The file is password protected --> LimeWire20.dll NOTE! The file is password protected --> logicrypto.jar NOTE! The file is password protected --> looks.jar NOTE! The file is password protected --> MessagesBundles.jar NOTE! The file is password protected --> mp3sp14.jar NOTE! The file is password protected --> ProgressTabs.jar NOTE! The file is password protected --> clink.jar NOTE! The file is password protected --> commons-httpclient.jar NOTE! The file is password protected --> commons-logging.jar NOTE! The file is password protected --> daap.jar NOTE! The file is password protected --> GenericWindowsUtils.dll NOTE! The file is password protected --> i18n.jar NOTE! The file is password protected --> icu4j.jar NOTE! The file is password protected --> id3v2.jar NOTE! The file is password protected --> jcraft.jar NOTE! The file is password protected --> jl011.jar NOTE! The file is password protected --> jmdns.jar NOTE! The file is password protected --> LimeWire.exe NOTE! The file is password protected --> LimeWire.jar NOTE! The file is password protected --> LimeWire20.dll NOTE! The file is password protected --> logicrypto.jar NOTE! The file is password protected --> looks.jar NOTE! The file is password protected --> MessagesBundles.jar NOTE! The file is password protected --> mp3sp14.jar NOTE! The file is password protected --> ProgressTabs.jar NOTE! The file is password protected 20051116204623.zip ArchiveType: ZIP NOTE! The whole archive is password protected C:\RECYCLER\S-1-5-21-448539723-507921405-839522115-1005 Dc18.rar ArchiveType: RAR NOTE! The archive is created by multiple volumes Error! Could not change directory: System Volume Information C:\WINDOWS\$NtUninstallKB835732$ reg00005 [DETECTION] Contains signature of the worm WORM/CodBot.20959 WAS DELETED! C:\WINDOWS\system32\config default Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! default.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SAM.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! SECURITY.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! software.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! system.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! End of scan: mardi 13 décembre 2005 14:32 Time taken: 90:24 min 4614 directories were scanned 101704 files were scanned 17 warning messages were issued 3 files were deleted 0 files were repaired 5 detections Le scan Panda est en cours... mais je suppose qu'on va me dire autre-chose avec ce que je vois dans ce rapport comme noms. -
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Ok Charles, c'est transmis merci. On n'a plus qu'à se laisser pousser la barbe... -
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Bonjour à tous, Voici le scan Panda en attendant la suite... Incident Status Location Adware:adware/maxifiles Not desinfected C:\PROGRAM FILES\FICHIERS COMMUNS\InetGet Adware:adware/exact.bargainbuddyNot desinfected Windows Registry -
Log HJT[Abandonné because P2P]
Apollo a répondu à un(e) sujet de Apollo dans Analyses et éradication malwares
Salut BipBip et Charles, Transmis le message de BipBip concernant les multiples apparitions dans le panneau; j'attends la suite. Charles, Il est évident que je déconseille toujours les logiciels P2P; quant au XP du moyen-âge, va savoir pourquoi il est toujours là. J'ai une petite idée, comme beaucoup de monde sûrement... Je posterai le rapport Antivir dès que je l'aurais reçu. T'as essayé la machine à courir? -
Bonsoir, Après avoir admiré ce beau panneau de configuration, j'ai conseillé d'appliquer la procédure avant Hijackthis et analyse du rapport d'Antivir et HJT; je poste tout de même un premier log pour voir les belles infections qu'il doit y avoir. Logfile of HijackThis v1.99.1 Scan saved at 18:06:18, on 12/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\System32\ELAN.exe C:\WINDOWS\System32\GSICON.EXE C:\WINDOWS\System32\dslagent.exe C:\Program Files\D-Tools\daemon.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Shareaza\Shareaza.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\ZonejeuX\GRoom\GroomAgent.exe C:\Program Files\Namtuk\Capture My Screen\CaptureMyScreen.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\INSTAN~1\bin\CMCENT~1.EXE C:\PROGRA~1\INSTAN~1\bin\INSTAN~1.EXE C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: phoneaccess Class - {5054F860-748D-4840-B7B4-DDDB428421AF} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [RemoveElanIcon] C:\WINDOWS\System32\ELAN.exe O4 - HKLM\..\Run: [AME_CSA] rundll32 AmeCSA.cpl,RUN_DLL O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008 O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE /partner ML1 O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [services32] C:\Program Files\Fichiers communs\Windows\mc-48-555-0000027.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - Startup: desktop(2)(2)(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(2)(3).ini O4 - Startup: desktop(2)(2)(2)(2).ini O4 - Startup: desktop(2)(2)(2)(3)(2).ini O4 - Startup: desktop(2)(2)(2)(3).ini O4 - Startup: desktop(2)(2)(2)(4).ini O4 - Startup: desktop(2)(2)(2).ini O4 - Startup: desktop(2)(2)(3)(2)(2).ini O4 - Startup: desktop(2)(2)(3)(2).ini O4 - Startup: desktop(2)(2)(3)(3).ini O4 - Startup: desktop(2)(2)(3).ini O4 - Startup: desktop(2)(2)(4)(2).ini O4 - Startup: desktop(2)(2)(4).ini O4 - Startup: desktop(2)(2)(5).ini O4 - Startup: desktop(2)(2).ini O4 - Startup: desktop(2)(3)(2)(2)(2).ini O4 - Startup: desktop(2)(3)(2)(2).ini O4 - Startup: desktop(2)(3)(2)(3).ini O4 - Startup: desktop(2)(3)(2).ini O4 - Startup: desktop(2)(3)(3)(2).ini O4 - Startup: desktop(2)(3)(3).ini O4 - Startup: desktop(2)(3)(4).ini O4 - Startup: desktop(2)(3).ini O4 - Startup: desktop(2)(4)(2)(2).ini O4 - Startup: desktop(2)(4)(2).ini O4 - Startup: desktop(2)(4)(3).ini O4 - Startup: desktop(2)(4).ini O4 - Startup: desktop(2)(5)(2).ini O4 - Startup: desktop(2)(5).ini O4 - Startup: desktop(2)(6).ini O4 - Startup: desktop(2).ini O4 - Startup: desktop(3)(2)(2)(2)(2).ini O4 - Startup: desktop(3)(2)(2)(2).ini O4 - Startup: desktop(3)(2)(2)(3).ini O4 - Startup: desktop(3)(2)(2).ini O4 - Startup: desktop(3)(2)(3)(2).ini O4 - Startup: desktop(3)(2)(3).ini O4 - Startup: desktop(3)(2)(4).ini O4 - Startup: desktop(3)(2).ini O4 - Startup: desktop(3)(3)(2)(2).ini O4 - Startup: desktop(3)(3)(2).ini O4 - Startup: desktop(3)(3)(3).ini O4 - Startup: desktop(3)(3).ini O4 - Startup: desktop(3)(4)(2).ini O4 - Startup: desktop(3)(4).ini O4 - Startup: desktop(3)(5).ini O4 - Startup: desktop(3).ini O4 - Startup: desktop(4)(2)(2)(2).ini O4 - Startup: desktop(4)(2)(2).ini O4 - Startup: desktop(4)(2)(3).ini O4 - Startup: desktop(4)(2).ini O4 - Startup: desktop(4)(3)(2).ini O4 - Startup: desktop(4)(3).ini O4 - Startup: desktop(4)(4).ini O4 - Startup: desktop(4).ini O4 - Startup: desktop(5)(2).ini O4 - Startup: desktop(5).ini O4 - Startup: Groom Agent.lnk = C:\Program Files\ZonejeuX\GRoom\GroomAgent.exe O4 - Global Startup: desktop(2)(2)(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(2)(3)(2).ini O4 - Global Startup: desktop(2)(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(2)(4).ini O4 - Global Startup: desktop(2)(2)(2).ini O4 - Global Startup: desktop(2)(2)(3)(2)(2).ini O4 - Global Startup: desktop(2)(2)(3)(2).ini O4 - Global Startup: desktop(2)(2)(3)(3).ini O4 - Global Startup: desktop(2)(2)(3).ini O4 - Global Startup: desktop(2)(2)(4)(2).ini O4 - Global Startup: desktop(2)(2)(4).ini O4 - Global Startup: desktop(2)(2)(5).ini O4 - Global Startup: desktop(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(2).ini O4 - Global Startup: desktop(2)(3)(2)(3).ini O4 - Global Startup: desktop(2)(3)(2).ini O4 - Global Startup: desktop(2)(3)(3)(2).ini O4 - Global Startup: desktop(2)(3)(3).ini O4 - Global Startup: desktop(2)(3)(4).ini O4 - Global Startup: desktop(2)(3).ini O4 - Global Startup: desktop(2)(4)(2)(2).ini O4 - Global Startup: desktop(2)(4)(2).ini O4 - Global Startup: desktop(2)(4)(3).ini O4 - Global Startup: desktop(2)(4).ini O4 - Global Startup: desktop(2)(5)(2).ini O4 - Global Startup: desktop(2)(5).ini O4 - Global Startup: desktop(2)(6).ini O4 - Global Startup: desktop(2).ini O4 - Global Startup: desktop(3)(2)(2)(2)(2).ini O4 - Global Startup: desktop(3)(2)(2)(2).ini O4 - Global Startup: desktop(3)(2)(2)(3).ini O4 - Global Startup: desktop(3)(2)(2).ini O4 - Global Startup: desktop(3)(2)(3)(2).ini O4 - Global Startup: desktop(3)(2)(3).ini O4 - Global Startup: desktop(3)(2)(4).ini O4 - Global Startup: desktop(3)(2).ini O4 - Global Startup: desktop(3)(3)(2)(2).ini O4 - Global Startup: desktop(3)(3)(2).ini O4 - Global Startup: desktop(3)(3)(3).ini O4 - Global Startup: desktop(3)(3).ini O4 - Global Startup: desktop(3)(4)(2).ini O4 - Global Startup: desktop(3)(4).ini O4 - Global Startup: desktop(3)(5).ini O4 - Global Startup: desktop(3).ini O4 - Global Startup: desktop(4)(2)(2)(2).ini O4 - Global Startup: desktop(4)(2)(2).ini O4 - Global Startup: desktop(4)(2)(3).ini O4 - Global Startup: desktop(4)(2).ini O4 - Global Startup: desktop(4)(3)(2).ini O4 - Global Startup: desktop(4)(3).ini O4 - Global Startup: desktop(4)(4).ini O4 - Global Startup: desktop(4).ini O4 - Global Startup: desktop(5)(2)(2).ini O4 - Global Startup: desktop(5)(2).ini O4 - Global Startup: desktop(5)(3).ini O4 - Global Startup: desktop(5).ini O4 - Global Startup: desktop(6)(2).ini O4 - Global Startup: desktop(6).ini O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: palstart(2).exe O4 - Global Startup: palstart.exe O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing) O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing) O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/eng/boards_2_0_0_21.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-30.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5054F860-748D-4840-B7B4-DDDB428421AF} (phoneaccess Class) - http://ip.sponsoradulto.com/cab/4/fr/phoneaccess.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1122920828967 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {701DC9DC-ACD5-4E94-85E3-F3F1ED68611A} (CWebClientCtl Object) - http://download.paltalk.com/webclient_prod...ebclientctl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {E9790C6C-DCAA-4E4F-8048-FFEC3B62DFED} (VOGWeb2 Class) - http://216.32.89.203/activex/vogweb29.cab O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...rcabinstall.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C2} (GameDesire Pool 9) - http://67.15.101.3/g_bin/eng/billard9_2_0_0_24.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe O23 - Service: MAPI Mail Client (MAPI) - Unknown owner - C:\WINDOWS\System32\mapi32.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Bonne soirée à tous et merci d'avance. (il y a du sermon dans l'air, je le sens...)
-
Re, Ce ne serait pas juste de ne pas vous transmettre les remerciements de Mireille car c'est vous qui avez tout le mérite! A bientôt. EDIT: Merci Charles, je n'y manquerai pas, bon week-end à toi aussi.
-
Bonjour et merci Jack, Je transmets à la personne concernée qui me dira si son pc tourne bien maintenant. Merci encore à tous ceux qui font un travail remarquable pour nous venir en aide! Bon week-end.
-
Up please. Bonjour à tous!
-
Merci tesgaz, je vais voir ça de plus près.
-
Bonsoir, Voilà, je suis le seul utilisateur de mon ordi et je voudrais savoir comment faire pour que Windows démarre ma session sans que j'aie besoin de cliquer sur le bouton avec mon nom dans l'écran Bienvenue. Auparavant, la session démarrait sans cela et je ne sais pas pourquoi je dois chaque fois cliquer sur ce bouton maintenant... Merci d'avance et bonne soirée.
-
Bonsoir, Voici la suite: Incident Status Location Possible Virus. Not desinfected C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\winks\programmes MSN.zip[NudgeMania.exe] Adware:Adware/Lop Not desinfected C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\setup\securite\lopremover.zip[lopremover.exe] ----------------------------- Logfile of HijackThis v1.99.1 Scan saved at 14:40:30, on 09.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\Program Files\Micro Application\MediaDICO\MediaDICO.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Skype\Phone\Skype.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Webshots\webshots.scr C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\setup\securite\HijackThis.exe C:\Program Files\MSN Messenger\msnmsgr.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Messenger\msmsgs.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe O4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB002" /M "Stylus DX3800" O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKCU\..\Run: [MediaDico] C:\Program Files\Micro Application\MediaDICO\MediaDICO.exe Lancement O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [DynAdvance Notifier] C:\Program Files\DynAdvance\DynAdvance Notifier\MailNotifier.Exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~2\bin\resources\WebMenuImg.htm O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar4.dll/cmwordtrans.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar4.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar4.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar4.dll/cmsearch.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar4.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\System32\ZipToA.exe Merci de la suite que vous réserverez à ce sujet. Bonne soirée.
-
Bonne nuit aussi Charles, je vais étaler la mienne aussi lol.
-
Il est vai que je reste souvent tard quand je cherche une solution pour quelqu'un que j'apprécie. Et puis, je sais toujours sur qui je vais tomber la nuit Je viens m'instruire également! Mais je me suis déjà demandé, en voyant l'heure de tes posts, quand tu trouvais le temps de ronfler un peu...
-
Re Charles, Un problème avec Lopremover, son antivirus réagit au quart de tour quand elle le télécharge; une solution? Chez moi, Kaspersky ne réagit pas mais A2 oui.
-
A demain pour la suite des (més)aventures de Mireille, avec la bonne nouvelle à la fin je l'espère pour elle! Mais je te fais confiance ainsi qu'à tes compères du forum sécurité.
-
Je suis toujours édifié par la vitesse avec laquelle tu réponds et fais tes analyses; je t'envie beaucoup! Peut-elle désinstaller Antivir?
-
Salut Charles, Merci d'avance; Antivir a quand-même fichu 6 ou 7 "machins" en quarantaine d'après les captures que j'ai pu voir dans un email.
-
Bon, le log HJT ne reste pas avec l'édition du post (trop long?); je le remets donc ici. Logfile of HijackThis v1.99.1 Scan saved at 21:55:59, on 07.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Micro Application\MediaDICO\MediaDICO.exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Logitech\Video\FxSvr2.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Webshots\webshots.scr C:\Program Files\Lavalys\EVEREST Home Edition\everest.bin C:\WINDOWS\system32\taskmgr.exe C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe c:\program files\mcafee.com\shared\mghtml.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\vso\OasClnt.exe C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\setup\securite\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fsersmdcpyc.com/aYNJeicwTSbHv86...qS/HeVhiuPe.cgi R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {25E8E309-DB05-D807-BF27-283247060C4D} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {7E2B16AF-46DB-DC5F-E91E-33D483D39481} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NAV_Update] C:\NAV_Update.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe O4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB002" /M "Stylus DX3800" O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [MediaDico] C:\Program Files\Micro Application\MediaDICO\MediaDICO.exe Lancement O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [LDM] \Program\ O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [incrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c O4 - HKCU\..\Run: [jump inside] C:\DOCUME~1\Mireille\APPLIC~1\OOZETI~1\City the.exe O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [DynAdvance Notifier] C:\Program Files\DynAdvance\DynAdvance Notifier\MailNotifier.Exe O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~2\bin\resources\WebMenuImg.htm O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar4.dll/cmwordtrans.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar4.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar4.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar4.dll/cmsearch.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar4.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {45E83043-1F6F-4D22-A5E7-0138EA171B49} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppD...sharingctrl.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1432acc8ba99d5...RdxIE601_fr.cab O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200411...meInstaller.exe O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {A977FF0C-8757-4E76-8533-482F91946233} (Pmang & SayClub Login Control) - http://dl.sayclub.com/sayclub/sayctl/sayax.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O18 - Protocol: bw+0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: offline-8876480 - {414B6776-66C8-4069-9FC2-6F746637F98E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\System32\ZipToA.exe
-
Bonsoir les as de la sécurité, Bon, le problème d'arrêt de pc semblait bien être dû à la surchauffe du processeur. Ceci dit, voici les rapports enfin complets d'Antivir et de Hijackthis: Scan Antivir: Date of preparation of the report file: mercredi, 7. décembre 2005 19:26 AVSCAN.EXE : 7.0.0.7 446504 02/12/2005 12:18:39 ANTIVIR3.VDF : 6.32.18.79 12288 04/12/2005 15:52:53 Jobname: 'Local Hard Disks' Scanning for 255083 virus strains and unwanted programs. Licensed to: AntiVir PersonalEdition Classic Serialnumber: 0000149996-WURGE-0001 Platform: Windows XP Windowsversion: (Service Pack 2) [5.1.2600] Username: Mireille Computername: BRISSONNETTE_M Versioninformations: AVSCAN.DLL : 7.0.0.7 41512 02/12/2005 12:18:38 LUKE.DLL : 7.0.0.7 110632 02/12/2005 12:18:41 LUKERES.DLL : 7.0.0.7 27176 02/12/2005 12:18:41 AVEWIN32.DLL : 6.32.0.100 1012224 02/11/2005 12:01:48 AVPREF.DLL : 6.33.0.0 38440 08/11/2005 07:42:34 AVREP.DLL : 6.32.1.1 1572904 02/12/2005 12:18:43 AVPACK32.DLL : 6.32.1.1 327720 30/11/2005 22:12:34 AVREG.DLL : 6.31.0.90 27688 28/07/2005 10:06:36 NETNT.DLL : 6.32.0.0 6696 27/09/2005 07:56:50 NETNW.DLL : 6.32.0.0 9768 27/09/2005 07:56:50 Start of the scan: mercredi, 7. décembre 2005 19:26 Start scanning bootsectors: Bootsector 'C:' [NOTE] No virus was found! Start scanning the registry. The registry was scanned ( 68 files ). Start the file scan: C:\hiberfil.sys [WARNING] The file could not be opened! C:\pagefile.sys [WARNING] The file could not be opened! C:\Thumbs.dble [WARNING] The file could not be opened! C:\$CTJTMP\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Ma musique\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Ma musique\My Playlists\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Ma musique\Sample Playlists\00141A6C\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Ma musique\Sync Playlists\0104C90C\virginie\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\Alexandro Bahtir é Igor\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\ami\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\arsim fersan é sherif\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\chanteur\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\copine de vevey\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\Dances\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\les drapeaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\meryl kim é kelly\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\mes montages\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\Moi\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\Jennifer\Moi\jenny\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\jumelle\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\Avatar\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\avatar msn 7\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\extra\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\extra\msn 7.0 emoticons animées\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\gallery2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\gros animée\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\gros fixe\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\msn gif plus\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\petit\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\petit animee modifier pour msn\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\petit animer certain ne fonctionne pas avec msn attention\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\petit pour msn\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\Smil\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Avatars MSN\Smillie gros\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\EmoPack V1\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\EmoPack V10\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\EmoPack V13\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\EmoPack V3\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\awatar2\EmoPack V7\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Guerre-armes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Masques\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Noël\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Pack bleu\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Pack -3D-\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Pack Coca-Cola\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Pack-2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\Emotions\Vrac\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\images\smiley\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\new\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\smile\winks\moods\Moods&Muggins\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\enfants\Mes documents\Mes fichiers reçus\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\enfants\Mes documents\Mes images\Mes photos Logitech\Photos et vidéos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Jennifer\Mes documents\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Jennifer\Mes documents\Mes fichiers reçus\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Jennifer\Mes documents\Mes images\Mes photos Logitech\Photos et vidéos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Jennifer\Mes documents\Mes images\Tigres\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\LocalService\NTUSER.DAT [WARNING] The file could not be opened! C:\Documents and Settings\LocalService\ntuser.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [WARNING] The file could not be opened! C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\ntuser.dat [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\ntuser.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\chat256.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\chat512.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\chatmsg256.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\contactgroup256.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\index2.dat [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\profile256.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\user1024.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\user4096.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Application Data\Skype\coeurdevanilles\voicemail256.dbb [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Bureau\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Bureau\armony\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Bureau\securité\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\amitié_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Anniversaire\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\Amitiés\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\Amitiés\un sourire\Unsourire2_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\Bébés\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\Humour\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\photos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Diaporamas\video audio\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Fichiers MSN Messenger\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\jumelle\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\jumelle\soso\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Ma musique\musique Mimi\Tresor eCarte Cartes virtuelles animées animaux (gifs animés)_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\Nana lingerie\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes fichiers reçus\setup\MSN7\msn\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\anges\BEBE\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\anges\DAMES\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\anges\ENFANTS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\anges\PHOTOS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\CHATS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\CHEVAUX\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\CHIENS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\Divers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\LAPIN\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\LICORNE\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\OISEAUX\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\Oursons\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\Papillons\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Animaux\souris\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\bebe\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\bebe anges\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\blinkies\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\bordures\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\cadres\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\charlotte aux fraises\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\dames\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\dentelles\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\dessins\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Disney\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\divers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\explosion\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Fan\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\fond blanc\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\fond bleu\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\fond noir\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\peintre\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fee\photos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fleurs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fond ecran net\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\fonds\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\anges\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\animaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\baby\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\cartoon\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\Fee\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\Fee\divers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\feu\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\fleurs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\globes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\musiques\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\Noël\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\pokemon\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\gifs\web\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Globes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\halloween2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\ALIEN BAG\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\ANIMAUX\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\ARCHITECTURE\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\FETES\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\FLEURS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\FOND1\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\INDIA\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\MER\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\NATIONAL PARC\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\PAYSAGE\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\Textile Designs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\TEXTURES\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images corel\WILDNESS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images indiens\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images jacky\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\images mistral\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\img_paque_divers\paque 01\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\img_paque_divers\paques\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\jumelle\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\licorne\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\maison\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\maison\Manga\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\maison\Manga\Pokemon\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\maison\Manga\sakura\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\arts\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\cadres\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\coeurs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\dentelles\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\dessins\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\elipses\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\fleurs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\Forme portes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\masque duotang\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\motifs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\vases\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\vertical\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\masques\étoile\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Mes photos Logitech\Mireille\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Mes photos Logitech\Photos et vidéos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Mes photos Logitech\Photos et vidéos\vivi\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\Doll Armony\DOLL\img\robes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\Cahier de charges de site web à compléter directement en ligne - www_joliespages_com_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\Formulaire de contact Page-Web_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\planche visite\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\Tuningmania autocollant_fichiers\Dra_1_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\Tuningmania autocollant_fichiers\Link_left_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\mireille originaux\divers sites\NET CONTACT\Tuningmania autocollant_fichiers\Link_Right_fichiers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Mireille régime\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Nouveau dossier\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\ornements\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\papier à lettres\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\papier à lettres\Horizontales\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\papier à lettres\Papier animés\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\papier à lettres\Verticales\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\paques\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\Denton lund\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\Jim Warren\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\jonathonart\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\josephine wall peintre\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\louisroyo\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\Mary Baxter St-Clair\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\terry ridlin\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\Thomas Kinkade\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\peintres\valerie tabor smith\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\polices\print\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\print2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\père noël\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Anges\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Annimaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Bébés\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\halloween\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Noel ruth\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Paques2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Poupons\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\psp\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Ruth Morehed\Valentin\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\Sara-Kay\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\sirenes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\sparkslink\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\tubes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\valentin\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorian\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\anges\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\divers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\floral\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\fonds\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\personnes\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians à moi\poupées\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\victorians_net\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Mes images\webschots\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\astuce archives\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\Actuelle\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\MARS\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\originaux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\photos msn\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\vieux\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\vieux\aout04\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\vieux\juillet04\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\vieux\juin04\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\vieux\septembre004\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Mireille\webcamphotos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Tendresse\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Tendresse\login\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\divers\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\divers\Mail\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Franky\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Fred\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\fred1\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Gianni\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Gianni\Nouveau dossier\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Gianni\Nouveau dossier (2)\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\julien\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Max\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Max\img jpeg\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Max\img psd\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Max\photos max +\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\anniversaire michel\22.10.05\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\corinne\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\corinne\chat\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\corinne\images\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\corinne\juge\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\img\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\privé\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\privé\mails site\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Michel\privé\photo\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\new\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\new\Fontaine\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\new\videos\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\new\videos\AVI\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Olivier\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Olivier\sex\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\Pascal\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\thiery\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\guy\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\Marco\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\mecs\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\michel\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\Mike\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\msnjob\Vanilles\trier\yann\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\My PSP8 Files\zip\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\My Skype Pictures\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\img\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\NANA Présentation\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\NANA Présentation\img\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\NANA Présentation\img\boutons\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\NANA Présentation\img-collection-automne2005\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\NANA Présentation\Travailles\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\Presentaion NANA 2\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\Presentation NANA\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\Presentation NANA\img\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\mediabiulder\site\img\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\NANA+carte visite\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\NANA+carte visite\imprimer\Brochure\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\new 2006\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\new 2006\buro\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\pub\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Pub pour NANA\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Pub pour NANA\Nana depliant\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Pub pour NANA\Nana depliant\Nana depliant psd\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Pub pour NANA\Nana depliant\Nana depliant psd\psd calques pour modifications\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\1-ANA\Pub pour NANA\Nana depliant\Nana depliant- jpg\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\catalogue défilé\cad\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\compressee\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\compressee\Nouveau dossier\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\defil\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mireille\Mes documents\Nana\2-septembre 2005\catalogue lundi\defil\nathan\web11\Thumbs.dble [WARNING] The file could not be opened! C:\Documents and Settings\Mir
-
Salut Jack, Oui, c'est ce que j'ai conseillé en attendant le nettoyage du pc et éventuellement son dépannage en cas de problème plus grave. Merci à plus tard.
-
Bonjour, Il s'avère qu'il y a un problème de surchauffe du processeur, très certainement à l'origine de l'arrêt de la machine (81°C). Je pense que c'est la première chose dont il faut s'occuper; je reviendrais donc par après pour les infections présentes. Bonne journée à tous.
-
Re Charles, Le pc s'arrête après 20/30 min en mode normal et en mode sans echec il se coupe de suite ou quasiment (pas de reboot) Euh le memtest pour clé usb c'est quel téléchargement please? J'ai trouvé pour disquette mais elle n'a pas de lecteur... Everest ne donne que la température du HDD, pas du processeur; faut trouver la soluce pour ce problème pour avoir une chance de désinfecter. EDIT: j'ai trouvé pour Memtest.
-
Re, Il se passe quelque-chose que je n'ai pas encore rencontré: le pc ne reste pas allumé en mode sans échec! Cela devient difficile de faire des analyses comme ça; en mode normal il reste allumé 30 minutes maximum... Problème hardware?