

Maelysroma
Membres-
Compteur de contenus
29 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par Maelysroma
-
Rapport Hijackthis pour analyse
Maelysroma a répondu à un(e) sujet de Maelysroma dans Analyses et éradication malwares
Bonjour, Même manuellement il reste introuvable Rapport de kaspersky: ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Wednesday, December 28, 2005 12:27:46 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 28/12/2005 Kaspersky Anti-Virus database records: 167965 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 40121 Number of viruses found: 49 Number of infected objects: 444 Number of suspicious objects: 0 Duration of the scan process: 3738 sec Infected Object Name - Virus Name C:\Documents and Settings\Administrateur\Application Data\axisbuild\abiqbvoo.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\adggbgsq.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\aeocmpez.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\afrooyux.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ajnxvlah.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ajywdove.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\amdzpqxe.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\amkqpphn.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\anmfpexh.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\astfpeiu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\atdmjhdw.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\aypzzuyu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\baigecck.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\bfpsbffk.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\bkoeeogh.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\bmxkpjcp.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\bqthebqc.exe Infected: not-a-virus:AdWare.Win32.Lop.o C:\Documents and Settings\Administrateur\Application Data\axisbuild\bqxgtapa.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\bruxucng.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\bungetst.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\byeizzef.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\byfxvrcd.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\cakymqjf.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\camlmaok.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\cbiskytv.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\cbnlphye.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\cfzcvmer.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\cgmwpmae.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\coowoqlo.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\cuuqlsga.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\cxyukcmg.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\czlwhggj.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\daowbvwy.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\dbpokiew.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ddfimdaz.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\detwzuak.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ditychvs.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\dixzfoex.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\dnxezioy.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\dsyeegbw.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\dvrvrtlo.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\dwcujvqi.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\dxkkdexa.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ecuugyqq.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\equibgtq.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ewrebjwg.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\exkksaxa.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\exowcofk.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\exueenzd.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\eykovmyx.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\eytnduiw.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\fcueyfsd.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\fdgisebd.exe Infected: Trojan-Downloader.Win32.Swizzor.dv C:\Documents and Settings\Administrateur\Application Data\axisbuild\fevqfaib.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\ffbcposk.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\fmtzxsue.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\fncnwlgz.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\fvhoczao.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\gbwfizfc.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\gchlgwpy.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ggqhgptz.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\glelgfga.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\glqejwao.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\gmrccycf.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\goyinztm.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\gslohwpu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\gttbxsme.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\gujlkwve.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\gyisspcb.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\hewesihc.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\hgstcfad.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\hhmfdsfo.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\hrjwtpko.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\htbhrqsh.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\htjeqlmq.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\hzlqeqdx.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\isbbolxi.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ivjkganw.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\iwyncvmw.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\izbvqzgs.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\iztjlkjg.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jaxgrthi.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jflxxjrt.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\jgsdcvjo.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\jhcoktrx.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\jjqqaqja.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\jjvdtfty.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jkpvjtxm.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jqfswqjn.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jsoepivd.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jsxxcxms.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\juvadxos.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\jxkexmjf.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\jzrrxani.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\kdkizvde.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\kfagbetk.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\kfnfmvts.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\kgxfjqty.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\klzozecb.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\kmouglyp.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ktqbaywk.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\kumzwhvf.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\kvxsaaof.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\kvyebegv.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\lbqinjzu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\lcbdhhiy.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\lcoxaglt.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\lgbijurr.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\llomssuu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\loyqhnul.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\lpxfcfjj.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\lumgcekz.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\lvudwgna.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\lwnndejq.exe Infected: Trojan-Downloader.Win32.Swizzor.de C:\Documents and Settings\Administrateur\Application Data\axisbuild\lxbtxgmm.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\maeivoyo.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\maijrput.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\mcvrsifo.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\mddvmjxg.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\miokikwu.exe Infected: Trojan-Downloader.Win32.Swizzor.dv C:\Documents and Settings\Administrateur\Application Data\axisbuild\mjctlizp.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\mjcuyuij.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\msgutkyg.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\mtydiadk.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\mvwpglxw.exe Infected: Trojan-Downloader.Win32.Swizzor.ca C:\Documents and Settings\Administrateur\Application Data\axisbuild\mwdzpqyf.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\mzfukyej.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ndlyqarv.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\nogkopgx.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\nzgkjluk.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ocnpalho.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\odaiikia.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\odiwuruh.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\odvzkmmf.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ojehspir.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\omlfojyu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ooaynnna.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\opltkyvp.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\oqwyeuap.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ouauyihd.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\oyacqtwu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\oylqpfyb.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\pbrlcwxw.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\pjyqxler.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\pkiytszp.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\pmsypcvx.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\pnpbuanl.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\pnzsvsmq.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\poevqcuj.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\popwmppr.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\pruxukuu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\psaxkbfk.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\pukoxdum.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\puoajewf.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\pvrvoncc.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\pwdwfpba.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\qgtvuzvq.exe Infected: Trojan-Downloader.Win32.Swizzor.du C:\Documents and Settings\Administrateur\Application Data\axisbuild\qmtgkpif.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\qtkqzcha.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\qwoasumy.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\qyfjsjen.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\rcdogqql.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\rcwuhech.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\reaagwlr.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\rewnadqg.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\rppcduav.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\rslfcbdx.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\rsrkvtkz.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ruyphdxi.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\rvcngppv.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\rzppxlbx.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\sgahcofc.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\sixthsecondbits.exe Infected: Trojan-Downloader.Win32.Swizzor.cb C:\Documents and Settings\Administrateur\Application Data\axisbuild\smyxcfrt.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\snjuxgft.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ssnhvexb.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\stbmhazy.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\tapjqgjt.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\tfqtpeua.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\tgwgmkgn.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\thbtgveu.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\tktpskuu.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\togmjjql.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\tpzkcevz.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\tytvpnxn.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uacrwmuv.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ubtbvwsv.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ucbrjdhc.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uiiaykkm.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\ukfcounx.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\ulbjrtur.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\umogqsrc.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\umzqbjvs.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\upghdeyi.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uqghsbpf.exe Infected: Trojan-Downloader.Win32.Swizzor.ca C:\Documents and Settings\Administrateur\Application Data\axisbuild\urhdtmdp.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uswullbw.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uuiyoumr.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uvvrlywx.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\uwspinne.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\vbqjxalo.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\vdexqsrc.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\veuxffez.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\vixckppk.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\vrhpsvgy.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\vrzhhbod.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\vutkzlio.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\wgcxvumz.exe Infected: Trojan-Downloader.Win32.Swizzor.dv C:\Documents and Settings\Administrateur\Application Data\axisbuild\wjecbtoh.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\wmvxrgqz.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\wqlhnvmc.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\wsjckjqx.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\wudzfgvm.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\wwxkuxws.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xcvtrceo.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xcwedufz.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\xiltuecl.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xipchjmt.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xisqgtli.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\xkrymcug.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\xkypdrgv.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xoncehck.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xpsbfwhe.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\xvbbcpfg.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\xwvboxgi.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\xxusxvfi.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xyditwve.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\xyfgujxd.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\yaaqgavg.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\ybhxfieb.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\ydossxnf.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\yeogubpz.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Application Data\axisbuild\ynmkmlez.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\yqqodrag.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\yqsyoutg.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\yvvheriu.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\zfalabyn.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Application Data\axisbuild\zjhbrffv.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\zmvvrqew.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\zpeaaddf.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Application Data\axisbuild\zyetewqw.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Application Data\axisbuild\zyidifls.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Application Data\axisbuild\zynifbzp.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\1597c6.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\16acd92.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\16c9fe.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\283764.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\5c95a5.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\5de600.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\cde828.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\f02f52d4.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f0444974.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f04e391e.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f062c9b0.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f073f293.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f094693b.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f0f74f24.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f105fc9c.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f113faf6.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f11d9642.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f1349c56.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f135e2e4.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Local Settings\Temp\f1362f69.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1366009.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f1367265.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1369b0d.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f13735d9.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f1377c4b.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f137c705.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f1389e66.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1398ae4.exe Infected: Trojan-Downloader.Win32.Swizzor.dv C:\Documents and Settings\Administrateur\Local Settings\Temp\f1398dc6.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f139d711.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f13a105b.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f13a700f.exe Infected: Trojan-Downloader.Win32.Swizzor.di C:\Documents and Settings\Administrateur\Local Settings\Temp\f13a8d38.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f13d446b.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f13fa5c0.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f144b708.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1470946.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f14db4d3.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Local Settings\Temp\f153e328.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f15e7dbe.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f18e342a.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f196eb26.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1d0f0be.exe Infected: Trojan-Downloader.Win32.Swizzor.dr C:\Documents and Settings\Administrateur\Local Settings\Temp\f1d4121d.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1e93899.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f1f05086.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f207ce8c.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f20e9b53.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f2190db7.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f22615a9.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f2262378.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f22772c4.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f22b151b.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f2385f96.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f23af038.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f24d7256.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f27f90f7.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f2b2ef84.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f32c2cca.exe Infected: Trojan-Downloader.Win32.Swizzor.dj C:\Documents and Settings\Administrateur\Local Settings\Temp\f3c6ade5.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f3f1dcc2.exe Infected: Trojan-Downloader.Win32.Swizzor.dh C:\Documents and Settings\Administrateur\Local Settings\Temp\f41d1ca2.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\f9056a09.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Documents and Settings\Administrateur\Local Settings\Temp\Inside Program.exe Infected: Trojan-Downloader.Win32.Swizzor.dv C:\Documents and Settings\Administrateur\Local Settings\Temp\sta4.exe Infected: not-a-virus:AdWare.Win32.Lop.ag C:\Program Files\HijackThis\backups\backup-20051227-174859-528.dll Infected: Trojan-Downloader.Win32.Swizzor.bo C:\Program Files\HijackThis\backups\backup-20051227-180259-111.dll Infected: Trojan-Downloader.Win32.Swizzor.bo C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\02AF0AC9 Infected: Trojan-Downloader.Win32.IstBar.ge C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\031437DE Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\06A67A1D Infected: Trojan-Downloader.BAT.Ftp.b C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\07FF12C1 Infected: Trojan-Downloader.Win32.Dyfuca.dp C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\106F6E1C Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1550113A Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\155F4199.exe Infected: Backdoor.Win32.Rbot.fo C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C1D2040/data0002 Infected: not-a-virus:AdWare.Win32.Sahat.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C1D2040 Infected: not-a-virus:AdWare.Win32.Sahat.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C7263E2 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C750DDF Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C7837DB Infected: Trojan-Downloader.Win32.IstBar.ge C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C7B61D7 Infected: not-a-virus:AdWare.Win32.SideFind C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C7F0BD4 Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8235D0 Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C855FCD Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8809C9 Infected: Trojan-Downloader.Win32.IstBar.gm C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8C33C5 Infected: Trojan-Downloader.Win32.IstBar.go C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8F5DC2 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C9207BE Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C9631BB/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C9631BB/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C9631BB Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C995BB7/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C995BB7/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C995BB7 Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1E5F4102 Infected: Trojan-Downloader.Win32.Dyfuca.dp C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1F1F0ABE Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1FB21265 Infected: not-a-virus:AdWare.Win32.180Solutions C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1FED3910 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\22693F32 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\23BF1418 Infected: Trojan-Downloader.JS.Small.ag C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\248C1253.exe Infected: Backdoor.Win32.IrcContact.30 C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\25C56BDA Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\280E6A93.exe Infected: Backdoor.Win32.Rbot.pb C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\29EF7D01 Infected: Trojan-Downloader.Win32.VB.ez C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2BDA06F5 Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2E6D2897 Infected: Trojan-Downloader.Win32.Dyfuca.dc C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\315527D8 Infected: Trojan-Downloader.Win32.IstBar.gm C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\31BB1DE0 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\34831955 Infected: Trojan-Downloader.Win32.Dyfuca.ds C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\34864351 Infected: not-a-virus:AdWare.Win32.PurityScan.w C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\34896D4E Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\354D75D7 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\357F38FF Infected: Trojan-Clicker.Win32.VB.ei C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\35EA5BAB Infected: not-a-virus:AdWare.Win32.PurityScan.ak C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.i C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95/WISE0013.BIN Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\367A4E95 Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\38B97D73 Infected: Trojan-Downloader.Win32.TSUpdate.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\399B483F Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\399E723C Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39A11C38 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39A44634 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39A87031 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39AB1A2D Infected: not-a-virus:AdWare.Win32.Sahat.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3D4C59DE Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3D9B2091 Infected: Trojan-Downloader.Win32.VB.ez C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3F79519D Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40993264/data0002 Infected: not-a-virus:AdWare.Win32.Sahat.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40993264 Infected: not-a-virus:AdWare.Win32.Sahat.h C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40E14E15 Infected: Trojan-Downloader.Win32.Dyfuca.dp C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40E47811 Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40E8220E/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40E8220E/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40E8220E Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40EB4C0A Infected: not-a-virus:AdWare.Win32.MediaMotor.a C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40EE7607 Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40F22003/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40F22003/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\40F22003 Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43937C8D Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\45B27E43 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\48DC15DD Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4AB34E89 Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4CD2503F Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4DC770C0 Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\51D42084 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\52D30E4D Infected: Trojan-Downloader.Win32.VB.ez C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\546C51DC Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\56746776.exe Infected: Backdoor.Win32.IrcContact.30 C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\56AF5B35.exe Infected: Backdoor.Win32.IrcContact.30 C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\59572CBE Infected: Trojan.Win32.StartPage.nk C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\59C6538A Infected: not-a-virus:AdWare.Win32.WinAD.k C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5A255B10 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5E362D17 Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61040CCA Infected: Trojan-Downloader.Win32.TSUpdate.g C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\64271F01 Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\64E868BD Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\65B5170F Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\65E52FE8 Infected: Trojan-Downloader.Win32.IstBar.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6A5E21A8 Infected: not-a-virus:AdWare.Win32.WinAD.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6B8D49D9/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6B8D49D9/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6B8D49D9 Infected: Trojan-Downloader.Win32.TSUpdate.f C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\7146530E Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71AF4C60 Infected: Trojan-Downloader.Win32.Dyfuca.dp C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71B3765C Infected: not-a-virus:AdWare.Win32.SideFind C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71B62059 Infected: Trojan-Downloader.Win32.Dyfuca.gen C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71B94A55 Infected: Trojan-Downloader.Win32.IstBar.ge C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71BC7451 Infected: Trojan-Downloader.Win32.Dyfuca.dk C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71C01E4E Infected: not-a-virus:AdWare.Win32.SideFind C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71C3484A Infected: Trojan.Win32.StartPage.nk C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71C67247 Infected: Trojan-Downloader.Win32.IstBar.gm C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\71C91C43 Infected: Trojan-Downloader.Win32.IstBar.go C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\72FE5DDF Infected: not-a-virus:AdWare.Win32.EliteBar.z C:\Program F -
Rapport Hijackthis pour analyse
Maelysroma a répondu à un(e) sujet de Maelysroma dans Analyses et éradication malwares
Non pas en mode normal J'ai essayé comme tu me l'avais conseillé avec ajouter/suprimer (panneau de configuration) mais il n'aparaissait pas Nouveau rapport: StartupList report, 27/12/2005, 23:00:08 StartupList version: 1.52.2 Started from : C:\Program Files\HijackThis\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options * Including empty and uninteresting sections * Showing rarely important sections ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\HPZipm12.exe C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\LVComS.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HijackThis\HijackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage] *No files* Shell folders AltStartup: *Folder not found* User shell folders Startup: *Folder not found* User shell folders AltStartup: *Folder not found* Shell folders Common Startup: [C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage] HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe Shell folders Common AltStartup: *Folder not found* User shell folders Common Startup: *Folder not found* User shell folders Alternate Common Startup: *Folder not found* -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] *Registry value not found* [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe ccApp = "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" SpeedTouch USB Diagnostics = "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon LogitechVideoRepair = C:\Program Files\Logitech\Video\ISStart.exe LogitechVideoTray = C:\Program Files\Logitech\Video\LogiTray.exe NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe TrustMailPoke2 = C:\Documents and Settings\All Users\Application Data\Rdr Third Trust Mail\tick dent.exe AVGCtrl = C:\Program Files\AVPersonal\AVGNT.EXE /min HP Software Update = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run [OptionalComponents] *No values found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- File association entry for .EXE: HKEY_CLASSES_ROOT\exefile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .COM: HKEY_CLASSES_ROOT\comfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .BAT: HKEY_CLASSES_ROOT\batfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .PIF: HKEY_CLASSES_ROOT\piffile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\scrfile\shell\open\command (Default) = "%1" /S -------------------------------------------------- File association entry for .HTA: HKEY_CLASSES_ROOT\htafile\shell\open\command (Default) = C:\WINDOWS\System32\mshta.exe "%1" %* -------------------------------------------------- File association entry for .TXT: HKEY_CLASSES_ROOT\txtfile\shell\open\command (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] * StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT [{5945c046-1e7d-11d1-bc44-00c04fd912be}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub [{7790769C-0471-11d2-AF11-00C04FA35D02}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = %SystemRoot%\system32\ie4uinit.exe -------------------------------------------------- Enumerating ICQ Agent Autostart apps: HKCU\Software\Mirabilis\ICQ\Agent\Apps *Registry key not found* -------------------------------------------------- Load/Run keys from C:\WINDOWS\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs= -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=*Registry value not found* drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\WINDOWS\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: HIDDEN! .shb: HIDDEN! .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Verifying REGEDIT.EXE integrity: - Regedit.exe found in C:\WINDOWS - .reg open command is normal (regedit.exe %1) - Regedit.exe has no CompanyName property! It is either missing or named something else. - Regedit.exe has no OriginalFilename property! It is either missing or named something else. - Regedit.exe has no FileDescription property! It is either missing or named something else. Registry check failed! -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - (no file) - {9A804D46-9E19-8EFE-81A3-45B5F1316CF7} -------------------------------------------------- Enumerating Task Scheduler jobs: Symantec NetDetect.job -------------------------------------------------- Enumerating Download Program Files: [DirectAnimation Java Classes] CODEBASE = file://C:\WINDOWS\Java\classes\dajava.cab OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd [Microsoft XML Parser for Java] CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd [Office Update Installation Engine] CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab [HouseCall Control] CODEBASE = http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab [Java Plug-in 1.4.2_06] InProcServer32 = C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll CODEBASE = http://java.sun.com/products/plugin/autodl...indows-i586.cab [MsnMessengerSetupDownloadControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx CODEBASE = http://messenger.msn.com/download/MsnMesse...pDownloader.cab [Java Plug-in 1.4.2_06] InProcServer32 = C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll CODEBASE = http://java.sun.com/products/plugin/autodl...indows-i586.cab [shockwave Flash Object] InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\WINDOWS\System32\mswsock.dll NameSpace #2: C:\WINDOWS\System32\winrnr.dll NameSpace #3: C:\WINDOWS\System32\mswsock.dll Protocol #1: C:\WINDOWS\system32\mswsock.dll Protocol #2: C:\WINDOWS\system32\mswsock.dll Protocol #3: C:\WINDOWS\system32\mswsock.dll Protocol #4: C:\WINDOWS\system32\mswsock.dll Protocol #5: C:\WINDOWS\system32\rsvpsp.dll Protocol #6: C:\WINDOWS\system32\rsvpsp.dll Protocol #7: C:\WINDOWS\system32\mswsock.dll Protocol #8: C:\WINDOWS\system32\mswsock.dll Protocol #9: C:\WINDOWS\system32\mswsock.dll Protocol #10: C:\WINDOWS\system32\mswsock.dll Protocol #11: C:\WINDOWS\system32\mswsock.dll Protocol #12: C:\WINDOWS\system32\mswsock.dll Protocol #13: C:\WINDOWS\system32\mswsock.dll Protocol #14: C:\WINDOWS\system32\mswsock.dll Protocol #15: C:\WINDOWS\system32\mswsock.dll Protocol #16: C:\WINDOWS\system32\mswsock.dll Protocol #17: C:\WINDOWS\system32\mswsock.dll Protocol #18: C:\WINDOWS\system32\mswsock.dll Protocol #19: C:\WINDOWS\system32\mswsock.dll Protocol #20: C:\WINDOWS\system32\mswsock.dll -------------------------------------------------- Enumerating Windows NT/2000/XP services Pilote ACPI Microsoft: System32\DRIVERS\ACPI.sys (system) Pilote de contrôleur intégré Microsoft: System32\DRIVERS\ACPIEC.sys (system) Suppresseur d'écho acoustique (Noyau Microsoft): system32\drivers\aec.sys (manual start) Environnement de prise en charge de réseau AFD: \SystemRoot\System32\drivers\afd.sys (system) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN): System32\DRIVERS\alcan5wn.sys (manual start) SpeedTouch ADSL Modem ATM Transport: System32\DRIVERS\alcaudsl.sys (manual start) Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start) Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start) Avertissement: %SystemRoot%\System32\svchost.exe -k LocalService (disabled) Service de la passerelle de la couche Application: %SystemRoot%\System32\alg.exe (manual start) AntiVir Service: C:\Program Files\AVPersonal\AVGUARD.EXE (autostart) Gestion d'applications: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Protocole client ARP 1394: System32\DRIVERS\arp1394.sys (manual start) Pilote de média asynchrone RAS: System32\DRIVERS\asyncmac.sys (manual start) Contrôleur de disque dur IDE/ESDI standard: System32\DRIVERS\atapi.sys (system) Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart) ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start) atiide: System32\DRIVERS\atiide.sys (system) Protocole client ATM ARP: System32\DRIVERS\atmarpc.sys (manual start) Audio Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote audio Stub: System32\DRIVERS\audstub.sys (manual start) avgntdw: \??\C:\Program Files\AVPersonal\AVGNTDW.SYS (manual start) AntiVir Update: "C:\Program Files\AVPersonal\AVWUPSRV.EXE" (autostart) Service de transfert intelligent en arrière-plan: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Explorateur d'ordinateur: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) ATI Cabo AGP Filter: System32\DRIVERS\atisgkaf.sys (system) Décodeur sous-titre fermé: system32\DRIVERS\CCDECODE.sys (manual start) Symantec Event Manager: "C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe" (autostart) Symantec Password Validation: "C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe" (manual start) Symantec Settings Manager: "C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe" (autostart) Pilote de CD-ROM: System32\DRIVERS\cdrom.sys (system) Service d'indexation: %SystemRoot%\system32\cisvc.exe (manual start) Gestionnaire de l'Album: %SystemRoot%\system32\clipsrv.exe (disabled) Pilote d'adaptateur secteur Microsoft: System32\DRIVERS\CmBatt.sys (manual start) Pilote de batterie composite Microsoft: System32\DRIVERS\compbatt.sys (system) Application système COM+: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start) Services de cryptographie: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Lanceur de processus serveur DCOM: %SystemRoot%\system32\svchost -k DcomLaunch (autostart) Client DHCP: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote de disque: System32\DRIVERS\disk.sys (system) Service d'administration du Gestionnaire de disque logique: %SystemRoot%\System32\dmadmin.exe /com (manual start) dmboot: System32\drivers\dmboot.sys (disabled) Pilote de Gestionnaire de disque logique: System32\drivers\dmio.sys (system) dmload: System32\drivers\dmload.sys (system) Gestionnaire de disque logique: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Synthétiseur DLS du noyau Microsoft: system32\drivers\DMusic.sys (manual start) Client DNS: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) Filtre de décodeur DRM (Noyau Microsoft): system32\drivers\drmkaud.sys (manual start) Service de rapport d'erreurs: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Journal des événements: %SystemRoot%\system32\services.exe (autostart) Système d'événements de COM+: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start) ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart) Compatibilité avec le Changement rapide d'utilisateur: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) FltMgr: system32\drivers\fltmgr.sys (system) Pilote du Gestionnaire de volume: System32\DRIVERS\ftdisk.sys (system) Firewall Driver: \SystemRoot\system32\drivers\fwdrv.sys (system) Classificateur de paquets générique: System32\DRIVERS\msgpc.sys (manual start) Aide et support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Accès du périphérique d'interface utilisateur: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Pilote de classe HID Microsoft: System32\DRIVERS\hidusb.sys (manual start) IEEE-1284.4 Driver HPZid412: system32\DRIVERS\HPZid412.sys (manual start) Print Class Driver for IEEE-1284.4 HPZipr12: system32\DRIVERS\HPZipr12.sys (manual start) USB to IEEE-1284.4 Translation Driver HPZius12: system32\DRIVERS\HPZius12.sys (manual start) HTTP: System32\Drivers\HTTP.sys (manual start) HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start) Pilote pour clavier i8042 et souris sur port PS/2: System32\DRIVERS\i8042prt.sys (system) InstallDriver Table Manager: "C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start) Service COM de gravage de CD IMAPI: C:\WINDOWS\system32\imapi.exe (manual start) Pilote de processeur Intel: System32\DRIVERS\intelppm.sys (system) Pilote du pare-feu Windows IPv6: system32\drivers\ip6fw.sys (manual start) Pilote de filtre de trafic IP: System32\DRIVERS\ipfltdrv.sys (manual start) Pilote de tunnelage IP dans IP: System32\DRIVERS\ipinip.sys (manual start) Traducteur d'adresses réseau IP: System32\DRIVERS\ipnat.sys (manual start) Pilote IPSEC: System32\DRIVERS\ipsec.sys (system) Protocole IrDA: System32\DRIVERS\irda.sys (autostart) Service énumérateur IR: System32\DRIVERS\irenum.sys (manual start) Moniteur infrarouge: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote de bus Plug-and-Play ISA/EISA: System32\DRIVERS\isapnp.sys (system) Pilote de la classe Clavier: System32\DRIVERS\kbdclass.sys (system) Kerio HIPS Driver: \SystemRoot\system32\drivers\khips.sys (system) Mélangeur audio Wave de noyau Microsoft: system32\drivers\kmixer.sys (manual start) Kerio Personal Firewall 4: "C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe" (autostart) Serveur: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Station de travail: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Assistance TCP/IP NetBIOS: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) Machine Debug Manager: "C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart) Affichage des messages: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Partage de Bureau à distance NetMeeting: C:\WINDOWS\System32\mnmsrvc.exe (manual start) Pilote de la classe Souris: System32\DRIVERS\mouclass.sys (system) Pilote HID de souris: System32\DRIVERS\mouhid.sys (manual start) Redirecteur client WebDav: System32\DRIVERS\mrxdav.sys (manual start) MRXSMB: System32\DRIVERS\mrxsmb.sys (system) Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start) Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start) Proxy de service de répartition Microsoft: system32\drivers\MSKSSRV.sys (manual start) Proxy d'horloge de répartition Microsoft: system32\drivers\MSPCLOCK.sys (manual start) Proxy de gestion de qualité de répartition Microsoft: system32\drivers\MSPQM.sys (manual start) Pilote BIOS de gestion de systèmes Microsoft: System32\DRIVERS\mssmbios.sys (manual start) Convertisseur en T/site-à-site de répartition Microsoft: system32\drivers\MSTEE.sys (manual start) Codec NABTS/FEC VBI: system32\DRIVERS\NABTSFEC.sys (manual start) Service Norton AntiVirus Auto-Protect: "C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe" (autostart) NAVENG: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20050727.008\NAVENG.Sys (manual start) NAVEX15: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20050727.008\NavEx15.Sys (manual start) Connection TV/vidéo Microsoft: system32\DRIVERS\NdisIP.sys (manual start) Pilote TAPI NDIS d'accès distant: System32\DRIVERS\ndistapi.sys (manual start) NDIS mode utilisateur E/S Protocole: System32\DRIVERS\ndisuio.sys (manual start) Pilote réseau étendu NDIS d'accès distant: System32\DRIVERS\ndiswan.sys (manual start) Interface NetBIOS: System32\DRIVERS\netbios.sys (system) NetBT: System32\DRIVERS\netbt.sys (system) DDE réseau: %SystemRoot%\system32\netdde.exe (disabled) DSDM DDE réseau: %SystemRoot%\system32\netdde.exe (disabled) Ouverture de session réseau: %SystemRoot%\System32\lsass.exe (manual start) Connexions réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote réseau 1394: System32\DRIVERS\nic1394.sys (manual start) NLA (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Norton Unerase Protection Driver: \??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS (manual start) Norton Unerase Protection: C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE (autostart) Fournisseur de la prise en charge de sécurité LM NT: %SystemRoot%\System32\lsass.exe (manual start) Stockage amovible: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Pilote de filtre de trafic IPX: System32\DRIVERS\nwlnkflt.sys (manual start) Pilote de transfert de trafic IPX: System32\DRIVERS\nwlnkfwd.sys (manual start) Contrôleur hôte Texas Instruments IEEE 1394 compatible OHCI (Open Host Controller Interface): System32\DRIVERS\ohci1394.sys (system) Office Source Engine: C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE (manual start) Pilote de port parallèle: System32\DRIVERS\parport.sys (manual start) PCI Bus Driver: System32\DRIVERS\pci.sys (system) PCIIde: System32\DRIVERS\pciide.sys (system) Pcmcia: System32\DRIVERS\pcmcia.sys (system) Logitech QuickCam Express(PID_0920): system32\DRIVERS\LV532AV.SYS (manual start) Plug-and-Play: %SystemRoot%\system32\services.exe (autostart) Pml Driver HPZ12: C:\WINDOWS\system32\HPZipm12.exe (autostart) Services IPSEC: %SystemRoot%\System32\lsass.exe (autostart) Miniport réseau étendu (PPTP): System32\DRIVERS\raspptp.sys (manual start) Pilote processeur: System32\DRIVERS\processr.sys (system) Emplacement protégé: %SystemRoot%\system32\lsass.exe (autostart) Planificateur de paquets QoS: System32\DRIVERS\psched.sys (manual start) Pilote de liaison parallèle directe: System32\DRIVERS\ptilink.sys (manual start) Pilote de connexion automatique d'accès distant: System32\DRIVERS\rasacd.sys (system) Gestionnaire de connexion automatique d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Miniport réseau étendu (IrDA): System32\DRIVERS\rasirda.sys (manual start) Miniport réseau étendu (L2TP): System32\DRIVERS\rasl2tp.sys (manual start) Gestionnaire de connexions d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote PPPOE d'accès à distance: System32\DRIVERS\raspppoe.sys (manual start) Parallèle direct: System32\DRIVERS\raspti.sys (manual start) Rdbss: System32\DRIVERS\rdbss.sys (system) RDPCDD: System32\DRIVERS\RDPCDD.sys (system) Pilote de redirecteur de périphérique Terminal Server: System32\DRIVERS\rdpdr.sys (manual start) Gestionnaire de session d'aide sur le Bureau à distance: C:\WINDOWS\system32\sessmgr.exe (manual start) Pilote de filtre de lecture digitale de CD audio: System32\DRIVERS\redbook.sys (system) Routage et accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Accès à distance au Registre: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Localisateur d'appels de procédure distante (RPC): %SystemRoot%\System32\locator.exe (manual start) Appel de procédure distante (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart) QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start) Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C): System32\DRIVERS\RTL8139.SYS (manual start) Gestionnaire de comptes de sécurité: %SystemRoot%\system32\lsass.exe (autostart) SAVRT: \??\C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVRT.SYS (manual start) SAVRTPEL: \??\C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVRTPEL.SYS (system) SAVScan: C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe (manual start) ScriptBlocking Service: C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart) Carte à puce: %SystemRoot%\System32\SCardSvr.exe (manual start) Planificateur de tâches: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) SDdriver: \??\C:\WINDOWS\System32\Drivers\sddriver.sys (manual start) Secdrv: System32\DRIVERS\secdrv.sys (manual start) Connexion secondaire: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Notification d'événement système: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Pare-feu Windows / Partage de connexion Internet: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Détection matériel noyau: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Détrameur décalage BDA: system32\DRIVERS\SLIP.sys (manual start) Pilote de périphérique SMC IrCC Miniport: System32\DRIVERS\smcirda.sys (manual start) Symantec Network Drivers Service: "C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe" (manual start) Speed Disk service: C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE (autostart) Splitter audio du noyau Microsoft: system32\drivers\splitter.sys (manual start) Spouleur d'impression: %SystemRoot%\system32\spoolsv.exe (autostart) Pilote de filtre de restauration système: System32\DRIVERS\sr.sys (system) Service de restauration système: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Srv: System32\DRIVERS\srv.sys (manual start) Service de découvertes SSDP: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) Acquisition d'image Windows (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart) BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start) Pilote de bus logiciel: System32\DRIVERS\swenum.sys (manual start) Synthétiseur de table de sons GC noyau Microsoft: system32\drivers\swmidi.sys (manual start) MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{F058FAE7-B5F1-4AED-B58B-EBEBB692D779} (manual start) SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start) SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start) SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system) SymWMI Service: "C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe" (autostart) Périphérique audio système du noyau Microsoft: system32\drivers\sysaudio.sys (manual start) Journaux et alertes de performance: %SystemRoot%\system32\smlogsvc.exe (manual start) Téléphonie: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote du protocole TCP/IP: System32\DRIVERS\tcpip.sys (system) Pilote de périphérique terminal: System32\DRIVERS\termdd.sys (system) Services Terminal Server: %SystemRoot%\System32\svchost -k DComLaunch (manual start) Thèmes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Telnet: C:\WINDOWS\System32\tlntsvr.exe (disabled) Client de suivi de lien distribué: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart) Pilote de mise à jour microcode: System32\DRIVERS\update.sys (manual start) Hôte de périphérique universel Plug-and-Play: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) Onduleur: %SystemRoot%\System32\ups.exe (manual start) Pilote USB audio (WDM): system32\drivers\usbaudio.sys (manual start) Pilote parent générique USB Microsoft: system32\DRIVERS\usbccgp.sys (manual start) Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft: System32\DRIVERS\usbehci.sys (manual start) Concentrateur USB2: System32\DRIVERS\usbhub.sys (manual start) Pilote miniport de contrôleur hôte ouvert USB Microsoft: System32\DRIVERS\usbohci.sys (manual start) Classe d'imprimantes USB Microsoft: system32\DRIVERS\usbprint.sys (manual start) Pilote de scanneur USB: system32\DRIVERS\usbscan.sys (manual start) USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start) Carte vidéo VGA.: \SystemRoot\System32\drivers\vga.sys (system) Cliché instantané de volume: %SystemRoot%\System32\vssvc.exe (manual start) Horloge Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote ARP IP d'accès distant: System32\DRIVERS\wanarp.sys (manual start) Pilote WINMM de compatibilité audio WDM Microsoft: system32\drivers\wdmaud.sys (manual start) WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) Infrastructure de gestion Windows: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Service de numéro de série du lecteur multimédia portable: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Extensions du pilote WMI: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Carte de performance WMI: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start) Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0: \SystemRoot\System32\drivers\ws2ifsl.sys (system) Centre de sécurité: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Codec Teletext standard: system32\DRIVERS\WSTCODEC.SYS (manual start) Mises à jour automatiques: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Configuration automatique sans fil: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Service d'approvisionnement réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: *Registry value not found* -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- End of report, 37 832 bytes Report generated in 2,141 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only -
Rapport Hijackthis pour analyse
Maelysroma a répondu à un(e) sujet de Maelysroma dans Analyses et éradication malwares
Merci Charles pour tes indications que j'ai suivies à la lettre, désolée de ne répondre que maintenant, mais avec un pc qui s'éteint toutes les 5 - 10 min en mode sans échec, ce ne fut point évident, d'ailleurs j'ai été obligée de faire le scan Ewido en mode normal car il s'éteignait à chaque fois à peine arrivé à 20% de l'analyse Voici les rapports demandés: --------------------------------------------------------- ewido anti-malware - Rapport de scan --------------------------------------------------------- + Créé le: 21:50:05, 27/12/2005 + Somme de contrôle: E594D397 + Résultats du scan: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Nettoyer et sauvegarder HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Nettoyer et sauvegarder HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy : Nettoyer et sauvegarder HKU\.DEFAULT\Software\LQ -> Dialer.Generic : Nettoyer et sauvegarder HKU\S-1-5-21-1957994488-682003330-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{511F9316-771B-4953-A268-1C36DA667FE9} -> Dialer.Generic : Nettoyer et sauvegarder HKU\S-1-5-18\Software\LQ -> Dialer.Generic : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@casinopays[1].txt -> Spyware.Cookie.Casinopays : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@com[2].txt -> Spyware.Cookie.Com : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@crbanner.casinopays[2].txt -> Spyware.Cookie.Casinopays : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@promo.casinotropez[1].txt -> Spyware.Cookie.Casinotropez : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@server.iad.liveperson[2].txt -> Spyware.Cookie.Liveperson : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@statcounter[2].txt -> Spyware.Cookie.Statcounter : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder C:\Documents and Settings\Administrateur\Cookies\administrateur@www.casinotropez[1].txt -> Spyware.Cookie.Casinotropez : Nettoyer et sauvegarder C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\25E561S5\sideb[1].exe -> Spyware.EliteBar : Nettoyer et sauvegarder ::Fin du rapport MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\HPZipm12.exe C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\LVComS.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {9A804D46-9E19-8EFE-81A3-45B5F1316CF7} - (no file) O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TrustMailPoke2] C:\Documents and Settings\All Users\Application Data\Rdr Third Trust Mail\tick dent.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe Quant à la version de mon Norton c'est la 2004 -
Bonjour, Je fais appelle à vous car je rencontre différents problèmes sur mon pc: - PC extrêment lent - PC qui s'éteint tout seul - Apparition de fenêtres intempestives lors de la connexion sur internet Mon abonnement norton antivirus étant venu à terme, je souhaiterais également le désinstaller proprement et le remplacer par Antivir. Ci-dessous mon rapport Hijackthis après pré-nettoyage: Logfile of HijackThis v1.99.1 Scan saved at 14:54:07, on 27/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {9A804D46-9E19-8EFE-81A3-45B5F1316CF7} - C:\DOCUME~1\ADMINI~1\APPLIC~1\DEFAUL~1\vcheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TrustMailPoke2] C:\Documents and Settings\All Users\Application Data\Rdr Third Trust Mail\tick dent.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe Un tout grand merci d'avance pour l'aide que vous pourrez m'apporter.