Aller au contenu

lei

Membres
  • Compteur de contenus

    84
  • Inscription

  • Dernière visite

Tout ce qui a été posté par lei

  1. c es deja fait cela je viensde reverifier ....merci je m occuperai du reste demain au dodo................byby bon surf..............chez zebulon
  2. d autre part je n ai pas le fichiers lambrother ds mon ajout suppression programe je peut pas le desinstaller
  3. tu dis que si je nai pas installe moi meme ce logiciel de surveillance je suis tes instructions mais c es moi qui l ai tele charger donc est ce que je fais quand meme tes directives ou autre choses mais je prefere le virer car il n es pas fiable et appporte souci..confirme moi la procedure tchao merci lei
  4. voici dernier rapport Logfile of HijackThis v1.99.1 Scan saved at 21:13:50, on 05/02/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\DOCUME~1\BELDJE~1\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKLM\..\Run: [Windows System Tray] C:\WINDOWS\system32\fonts\system\explorer\mru\dlhost.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - Startup: Rappels du Calendrier Microsoft Works.lnk = C:\Program Files\MSWorks\Calendrier\WKCALREM.EXE O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe merci de votre
  5. j ai fait un scan et je suis infecte par 2 virus Trojan-Spy.Win32.IamBigBrother.91" et"Trojan-Spy.Win32.IamBigBrother.90 je n ai pas trouver de sites pr m aider a m en debarasser merci de votre aide a bientot
  6. pas de reponse que fais je merciiiiiiiiii
  7. bonsoir j ai eu du mal avec antivirpr le mettre a jour j ai desinstaller puis remis mais suis pas sur de bien l avoir fait y a til autre antivirus aussi fiable????? MERCI PR L ANALYSE RAPPORT EST CE QUE TT VA BIEN OU PAS Logfile of HijackThis v1.99.1 Scan saved at 22:33:09, on 03/02/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apps\ActivBoard\nhksrv.exe C:\WINDOWS\System32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe C:\WINDOWS\system32\fonts\system\explorer\mru\dlhost.exe C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\Program Files\MSWorks\Calendrier\WKCALREM.EXE C:\PROGRA~1\MSNMES~1\msnmsgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\Explorer.EXE C:\DOCUME~1\BELDJE~1\LOCALS~1\Temp\Répertoire temporaire 2 pour hijackthis_199.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKLM\..\Run: [Windows System Tray] C:\WINDOWS\system32\fonts\system\explorer\mru\dlhost.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [update Service] "C:\Program Files\Fichiers communs\Teknum Systems\update.exe" /startup O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background O4 - Startup: Rappels du Calendrier Microsoft Works.lnk = C:\Program Files\MSWorks\Calendrier\WKCALREM.EXE O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (file missing) O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (file missing) O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  8. oui effectivement depuis telecharge ce fichier lambrother ca beugg mais on peu t le virer je vais tes recommandationset je reecris merci
  9. j ai fait cela avalt de poster mon rapport exaxtement la meme proceduredois je le refaire ? antivir a du mal a ce mettre a jour je trouve est ce pr cela que je suis a nouveau infecte??,
  10. bonjour je poste ici mon rapport je pense avoir encore des virus ou autre malgre antivir et spybot merci de votre aide peut etre tt va bien merci Logfile of HijackThis v1.99.1 Scan saved at 14:50:37, on 02/02/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\AVPersonal\AVGNT.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\hidjaker\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKLM\..\Run: [WinLoad] C:\WINDOWS\system32\Winload.exe O4 - HKLM\..\Run: [WinLoad32] C:\WINDOWS\system32\Winload32.exe O4 - HKLM\..\Run: [Windows System Tray] C:\WINDOWS\system32\fonts\system\explorer\mru\dlhost.exe O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - Startup: Rappels du Calendrier Microsoft Works.lnk = C:\Program Files\MSWorks\Calendrier\WKCALREM.EXE O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  11. c es fait MERCI BEAUCOUP POUR TON AIDE J ESPERE QUE IL VA RESTER UN PEU PROPRE CET ORDI AVEC TOUT CA .......................ALORS JE NE PEUT QUE T ENVOYER VIRTUELLEMENT CA: byby et bonne continuation...............lei
  12. jte remercie c es mieux en francais .voila dernier rappport Logfile of HijackThis v1.99.1 Scan saved at 11:18:15, on 08/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apps\ActivBoard\nhksrv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\hidjaker\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - Startup: Rappels du Calendrier Microsoft Works.lnk = C:\Program Files\MSWorks\Calendrier\WKCALREM.EXE O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
  13. suis pas tre doue mais ttes en anglais mais bon jai fait mais tout es coches (apres selection speciale )et j ai tape sur remove mais ca fait rien (y a start mais c es pr refaire ce que j ai deja fait,y a regeditexplore try to fix remove et close j ai une info qui me dit root hkey local machin key systeme/controlset003/ services eventlogapplicatio ese etc.... et reason c:/program files msn toolbar suite /external/ese.dll does not exist a peu pres c es ca et me demande save as copy open regedit ou close ???,
  14. me revoila voici les rapports ******** 21:47: | Début de session, samedi 7 janvier 2006 | 21:47: Spy Sweeper démarrée 21:47: Analyse lancée avec la version des définitions 597 21:47: Démarrage de l’analyse de la mémoire 21:52: Analyse de la mémoire terminée, temps passé : 00:04:17 21:52: Démarrage de l’analyse du Registre 21:52: Trouvé Adware: edipol alloticket dialer 21:52: HKCR\interface\{cfbc1c5d-d33c-11d4-9269-00600868e56e}\ (8 traces secondaires) (ID = 125640) 21:52: HKLM\software\classes\interface\{cfbc1c5d-d33c-11d4-9269-00600868e56e}\ (8 traces secondaires) (ID = 125642) 21:52: HKLM\software\classes\webinstall.wwwinstall.1\ (3 traces secondaires) (ID = 125645) 21:52: HKCR\webinstall.wwwinstall.1\ (3 traces secondaires) (ID = 125648) 21:52: Trouvé Adware: instant access 21:52: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/eglivecam_1028.dll\ (1 traces secondaires) (ID = 128803) 21:52: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\system32\eglivecam_1028.dll (ID = 128824) 21:52: Trouvé Adware: navexcel navhelper 21:52: HKCR\appid\nhelper.dll\ (1 traces secondaires) (ID = 135511) 21:52: HKLM\software\classes\appid\nhelper.dll\ (1 traces secondaires) (ID = 135525) 21:52: Trouvé Adware: opistat 21:52: HKLM\software\opistat\ (6 traces secondaires) (ID = 136464) 21:52: Trouvé Adware: winantispyware 2005 21:52: HKCR\checkproduct2.checkproduct\ (5 traces secondaires) (ID = 527503) 21:52: HKCR\checkproduct2.checkproduct.1\ (3 traces secondaires) (ID = 527509) 21:52: HKCR\appid\checkproduct2.dll\ (1 traces secondaires) (ID = 527632) 21:52: HKCR\appid\{8c65aef6-e413-4314-815b-82717a3f1603}\ (1 traces secondaires) (ID = 527648) 21:52: HKCR\clsid\{c427b3e3-28dc-4001-9590-d99b6776119b}\ (15 traces secondaires) (ID = 527829) 21:52: HKCR\interface\{4f79d1c5-24f9-4e59-8022-604d4b41d5ca}\ (8 traces secondaires) (ID = 527937) 21:52: HKCR\typelib\{30ed49a5-ca6c-4918-b5f3-5e6818c91d8b}\ (9 traces secondaires) (ID = 528091) 21:52: HKLM\software\classes\checkproduct2.checkproduct\ (5 traces secondaires) (ID = 528199) 21:52: HKLM\software\classes\checkproduct2.checkproduct.1\ (3 traces secondaires) (ID = 528205) 21:52: HKLM\software\classes\appid\checkproduct2.dll\ (1 traces secondaires) (ID = 528341) 21:52: HKLM\software\classes\appid\{8c65aef6-e413-4314-815b-82717a3f1603}\ (1 traces secondaires) (ID = 528357) 21:52: HKLM\software\classes\clsid\{c427b3e3-28dc-4001-9590-d99b6776119b}\ (15 traces secondaires) (ID = 528538) 21:52: HKLM\software\classes\typelib\{30ed49a5-ca6c-4918-b5f3-5e6818c91d8b}\ (9 traces secondaires) (ID = 528800) 21:52: HKLM\software\classes\appid\{8c65aef6-e413-4314-815b-82717a3f1603}\ (1 traces secondaires) (ID = 543259) 21:52: HKCR\vapfm.creationnotifier\ (5 traces secondaires) (ID = 795157) 21:52: HKCR\vapfm.creationnotifier.1\ (3 traces secondaires) (ID = 795163) 21:52: HKCR\appid\{4d05a335-1a1c-46b3-bcff-7f25b326895c}\ (1 traces secondaires) (ID = 795173) 21:52: HKCR\clsid\{328ba26a-1619-47ee-a37d-7d7a6ab1b000}\ (12 traces secondaires) (ID = 795177) 21:52: HKCR\typelib\{4d05a335-1a1c-46b3-bcff-7f25b326895c}\ (9 traces secondaires) (ID = 795242) 21:52: HKLM\software\classes\vapfm.creationnotifier\ (5 traces secondaires) (ID = 795286) 21:52: HKLM\software\classes\vapfm.creationnotifier.1\ (3 traces secondaires) (ID = 795292) 21:52: HKLM\software\classes\appid\filecreationfilter.dll\ (1 traces secondaires) (ID = 795298) 21:52: HKLM\software\classes\appid\{4d05a335-1a1c-46b3-bcff-7f25b326895c}\ (1 traces secondaires) (ID = 795302) 21:52: HKLM\software\classes\clsid\{328ba26a-1619-47ee-a37d-7d7a6ab1b000}\ (12 traces secondaires) (ID = 795306) 21:52: HKLM\software\classes\typelib\{4d05a335-1a1c-46b3-bcff-7f25b326895c}\ (9 traces secondaires) (ID = 795371) 21:52: HKLM\system\currentcontrolset\control\class\{29ae0e04-08b8-4d2f-bfbe-83fb0ec73bb7}\ (3 traces secondaires) (ID = 795420) 21:52: Trouvé Adware: globalcs dialer 21:52: HKU\WRSS_Profile_S-1-5-21-4210259494-357464061-2299825339-1007\software\globalcs\ (1 traces secondaires) (ID = 126850) 21:52: HKU\WRSS_Profile_S-1-5-21-4210259494-357464061-2299825339-1006\software\globalcs\ (1 traces secondaires) (ID = 126850) 21:52: HKU\S-1-5-21-4210259494-357464061-2299825339-1005\software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0\ || goicfboogidikkejccmclpieicihhlpo bgdjdn (ID = 128845) 21:52: Analyse du Registre terminée, temps passé :00:00:37 21:52: Démarrage de l’analyse des cookies 21:52: Trouvé Spy Cookie: xiti cookie 21:52: farid@xiti[1].txt (ID = 3717) 21:52: Trouvé Spy Cookie: 247realmedia cookie 21:52: beldjelti@247realmedia[1].txt (ID = 1953) 21:52: Trouvé Spy Cookie: apmebf cookie 21:52: beldjelti@apmebf[1].txt (ID = 2229) 21:52: Trouvé Spy Cookie: bluestreak cookie 21:52: beldjelti@bluestreak[2].txt (ID = 2314) 21:52: Trouvé Spy Cookie: tradedoubler cookie 21:52: beldjelti@tradedoubler[2].txt (ID = 3575) 21:52: Trouvé Spy Cookie: weborama cookie 21:52: beldjelti@weborama[2].txt (ID = 3658) 21:52: beldjelti@xiti[1].txt (ID = 3717) 21:52: Analyse des cookies terminée, temps passé : 00:00:00 21:53: Démarrage de l’analyse des fichiers 21:53: c:\program files\winantispyware 2005 (ID = -2147472152) 21:53: c:\program files\navexcel (2 traces secondaires) (ID = -2147480574) 21:53: c:\program files\nsupdate (ID = -2147480929) 21:53: Trouvé System Monitor: pc tattletale 21:53: c:\windows\system32\explorer32 (1418 traces secondaires) (ID = -2147480485) 21:53: Trouvé Adware: webhancer 21:53: c:\program files\whinstall (ID = -2147480064) 21:53: Trouvé Adware: delfin 21:53: c:\program files\delfin (ID = -2147481128) 21:58: a0000651.dll (ID = 63817) 21:58: dc31.txt (ID = 83804) 21:58: dc24 (ID = 63918) 21:58: dc26.txt (ID = 83802) 22:00: a0000648.dll (ID = 83814) 22:05: upgradebrowser.htm (ID = 72070) 22:05: idletime.ocx (ID = 72076) 22:06: explorer.chm (ID = 72074) 22:09: wff.sys (ID = 150595) 22:10: pctt.exe (ID = 72061) 22:11: chattext.dll (ID = 72073) 22:11: autoupdateclient.exe (ID = 72062) 22:12: autoupdate.dll (ID = 72069) 22:12: controle.exe (ID = 72064) 22:14: instructions.htm (ID = 72065) 22:16: dc30.ini (ID = 188794) 22:17: Avertissement: Unhandled Archive Type 22:18: Analyse des fichiers terminée, temps passé : 00:25:47 22:18: Analyse complète terminée. Durée 00:31:04 22:18: Traces trouvées : 1661 22:27: Processus de suppression lancé. 22:27: Mise en quarantaine de toutes les traces : pc tattletale 22:28: Mise en quarantaine de toutes les traces : delfin 22:28: Mise en quarantaine de toutes les traces : edipol alloticket dialer 22:28: Mise en quarantaine de toutes les traces : globalcs dialer 22:28: Mise en quarantaine de toutes les traces : instant access 22:28: Mise en quarantaine de toutes les traces : navexcel navhelper 22:28: Mise en quarantaine de toutes les traces : opistat 22:28: Mise en quarantaine de toutes les traces : webhancer 22:28: Mise en quarantaine de toutes les traces : winantispyware 2005 22:28: Mise en quarantaine de toutes les traces : 247realmedia cookie 22:28: Mise en quarantaine de toutes les traces : apmebf cookie 22:28: Mise en quarantaine de toutes les traces : bluestreak cookie 22:28: Mise en quarantaine de toutes les traces : tradedoubler cookie 22:28: Mise en quarantaine de toutes les traces : weborama cookie 22:28: Mise en quarantaine de toutes les traces : xiti cookie 22:28: Processus de suppression lancé. Durée 00:01:14 ******** 21:36: | Début de session, samedi 7 janvier 2006 | 21:36: Spy Sweeper démarrée 21:37: Les définitions de logiciels espions ont été mises à jour. 21:47: | Fin de session, samedi 7 janvier 2006 | et Logfile of HijackThis v1.99.1 Scan saved at 22:34:12, on 07/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apps\ActivBoard\nhksrv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\WINDOWS\system32\cidaemon.exe C:\PROGRA~1\MSNMES~1\msnmsgr.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\hidjaker\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe voila jespere que c es mieux ....merci a+ j oubliai oui le pc est + lent par moment les programmes se bloquent et me demande de terminer maintenant je crois que c es tout comment le proteger malger antivirus et spyboot
  15. je ne le prend pas mal mais c es un peu charabia pr moi voila ce que easy a trouve comme fichiers inutiles il en fait quoi il les supprime de lui meme oou j ai manip a faire sinon j ai eu un blocage avec des coin de l ecran devenu noire puis c es revenu normal tu m a compris j espere merci a+ dis moi si j ai d autres choses a faire pr les malwares
  16. easy a trouver des fichiers inutiles mais moi je fais rien ils sont elimines seule j ai rien a faire a la fin du scan ca a bloque avec un crectangle noir puis s es revenu ........ je n ai pas trouve tous les fichiers a elimines c a dire C:\WINDOWS\system\RESTORE.INS[PSKILL.EXE] C:\WINDOWS\RESTORE.INS[PSKILL.EXE] es ce que je supprime ce que easy a trouver ds registre ou pas(y a peits ronds verts devant ) a+
  17. re pas trouver ce nom whinstall sur ajout suppresion je l ai pas?????
  18. re j ai fini scan et encore et toujours des petites choses voici le rapport Incident Statut Analyse Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\beldjelti\Cookies\beldjelti@bluestreak[1].txt Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\beldjelti\Cookies\beldjelti@weborama[2].txt Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\beldjelti\Cookies\beldjelti@xiti[1].txt Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\farid\Cookies\farid@xiti[1].txt Adware:Adware/WebHancer No Désinfecté C:\Program Files\whInstall\whAgent.inf Adware:Adware/WebHancer No Désinfecté C:\Program Files\whInstall\whInstaller.ini Spyware:spyware/web3000 No Désinfecté C:\WINDOWS\hhs.url Outil indésirable:Application/Pskill.A No Désinfecté C:\WINDOWS\RESTORE.INS[PSKILL.EXE] Outil indésirable:Application/Pskill.A No Désinfecté C:\WINDOWS\system\RESTORE.INS[PSKILL.EXE] Adware:adware/navipromo No Désinfecté C:\WINDOWS\system32\ynisukcw_nav.dat Dialer:dialer.b No Désinfecté C:\WINDOWS\tmlpcert2005
  19. bonjour je vais faire encore scan avec panda sinon j ai un message de l utilitaire configuration systeme qui me dit que je suis en demarrage selectif et me demande de faire demarrage normal je fais quoi? merci pr ton aide .a+
  20. voici rapport hijackthis: Scan saved at 00:04:24, on 07/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apps\ActivBoard\nhksrv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\hidjaker\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe ainsi que rapport scan ewido j espere que y a plus de microbe --------------------------------------------------------- + Créé le: 00:01:51, 07/01/2006 + Somme de contrôle: FF038806 + Résultats du scan: HKLM\SOFTWARE\Classes\Interface\{3947AC1D-DB09-4353-BBCC-55B97F5035EF} -> Dialer.Generic : Nettoyer et sauvegarder HKLM\SOFTWARE\Classes\Interface\{A58F3D09-4543-4396-8BE7-105F14DD6ED5} -> Dialer.Generic : Nettoyer et sauvegarder HKLM\SOFTWARE\Classes\TypeLib\{0E594D22-ACE6-43A2-BCDA-BB7C65D3FE8C} -> Dialer.Generic : Nettoyer et sauvegarder HKU\S-1-5-21-4210259494-357464061-2299825339-1005\Software\GlobalCS -> Dialer.Generic : Nettoyer et sauvegarder HKU\S-1-5-21-4210259494-357464061-2299825339-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Nettoyer et sauvegarder HKU\S-1-5-21-4210259494-357464061-2299825339-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03C543A1-C090-418F-A1D0-FB96380D601D} -> Dialer.Generic : Nettoyer et sauvegarder HKU\S-1-5-21-4210259494-357464061-2299825339-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Application Data\Mercora\MercoraClient\Data\MyPictures.dat -> Spyware.Grokster : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@2o7[1].txt -> Spyware.Cookie.2o7 : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@weborama[2].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder C:\Documents and Settings\beldjelti\Cookies\beldjelti@www.smartadserver[1].txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder C:\OEMCUST\TOOLS\WIN32\PSKILL.EXE -> Not-A-Virus.NetTool.Win32.PsKill : Nettoyer et sauvegarder C:\Program Files\MSN Messenger\riched20.dll -> Spyware.MyWebSearch : Nettoyer et sauvegarder C:\Program Files\Save -> Spyware.SaveNow : Nettoyer et sauvegarder C:\Program Files\Save\ReadMe.txt -> Spyware.SaveNow : Nettoyer et sauvegarder C:\Program Files\Save\save.cch -> Spyware.SaveNow : Nettoyer et sauvegarder C:\Program Files\whInstall\Webhdll.dll -> Spyware.WebHancer : Nettoyer et sauvegarder C:\Program Files\whInstall\whInstaller.exe -> Spyware.WebHancer : Nettoyer et sauvegarder C:\WINDOWS\Downloaded Program Files\UWAS5_0001_N57M0812NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Nettoyer et sauvegarder C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Nettoyer et sauvegarder C:\WINDOWS\system32\eglivecam_1028.dll -> Trojan.P2E.aa : Nettoyer et sauvegarder C:\WINDOWS\system32\f3PSSavr.scr -> Spyware.MyWebSearch : Nettoyer et sauvegarder C:\WINDOWS\system32\msclock32.dll -> Adware.NaviPromo : Nettoyer et sauvegarder ::Fin du rapport PENSE TU QUE JE PEUT GARDE EWIDO OU FAUT IL QUE JE LE SUPPRIME CAR DEJA ANTIVIR??????? merci beaucoup pr ton aide et si d autre conseils suis preneuse ......a+
  21. spyb ne detecte plus magiccontrol c es deja bien pour antivir il es en cours j essaie avec ewido il a deja trouve un cheval de troie je crois mais la ca bloque un peu je n arrive plus a agrandir l icone d ewido je vois pas la progression du scan et ordi es ralenti mais je continue pas genant scan antivir en meme tps que ewido resultat antivir Creation date of the report file: vendredi 6 janvier 2006 22:13 AntiVir®/XP (2000 + NT) PersonalEdition Classic Build 1114 of 04.11.2005 Mainprogram 6.32.00.51 of 03.11.2005 VDF file 6.33.0.102 (0) of 05.01.2006 This program is for PERSONAL USE only. Any other use is PROHIBITED. Informations regarding commercial versions of AntiVir may be obtained from: www.hbedv.com. Scanning for 275993 virus strains and unwanted programs. Licensed for: AntiVir Personal Edition Serial number: 0000149991-WURGE-0001 Please enter the workstation and contact name with phone number in this form: Name ___________________________________________ Street ___________________________________________ Town ___________________________________________ Phone/Fax ___________________________________________ Email ___________________________________________ Platform: Windows NT Workstation Windows version: 5.1 Build 2600 (Service Pack 2) Username: beldjelti Computername: LEIILAFA Processor: Pentium Working memory: 261616 KB free Version information: AVWIN.DLL : 6.32.00.51 561192 04.11.2005 07:50:54 AVEWIN32.DLL : 6.33.0.75 1008128 05.01.2006 23:48:22 AVGNT.EXE : 6.32.00.02 180327 03.11.2005 17:06:56 AVGUARD.EXE : 6.32.00.12 208424 03.11.2005 17:06:58 GUARDMSG.DLL : 6.30.00.02 94248 01.02.2005 10:24:12 AVGCMSG.DLL : 6.32.00.01 295029 03.11.2005 17:06:58 AVGNTDW.SYS : 6.31.00.01 32896 29.04.2005 08:07:16 AVPACK32.DLL : 6.32.00.02 319528 03.11.2005 16:57:42 AVGETVER.DLL : 6.30.00.00 24576 28.01.2005 17:10:20 AVSHLEXT.DLL : 6.30.00.01 40960 28.01.2005 17:10:22 AVSched32.EXE : 6.32.00.01 110632 20.09.2005 14:16:26 AVSched32.DLL : 6.30.00.00 122880 01.02.2005 10:24:12 AVREG.DLL : 6.31.00.05 41000 07.09.2005 16:34:50 AVRep.DLL : 6.33.00.94 1613864 04.01.2006 22:47:04 INETUPD.EXE : 6.32.00.53 262203 04.11.2005 07:49:30 INETUPD.DLL : 6.32.00.53 143360 04.11.2005 07:49:30 CTL3D32.DLL : 2.31.000 27136 28.08.2001 11:00:00 MFC42.DLL : 6.02.4131.0 1028096 20.08.2004 00:09:30 MSVCRT.DLL : 7.0.2600.2180 (xpsp_sp2_rtm.0408 MSVCRT.DLL : 7.0.2600.2180 343040 20.08.2004 00:09:34 CTL3DV2.DLL : No information Configuration file: Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI Name of report file: C:\Program Files\AVPersonal\LOGFILES\AVWIN.LOG Start path: C:\Program Files\AVPersonal Command line: Start mode: unknown Mode of report file: [ ] Do not create report [X] Overwrite report [ ] Append new report Data in report file: [X] Infected files [ ] Infected files with paths [ ] All scanned files [ ] Full information Abridge report file: [ ] Abridge report file Warnings in report: [X] Access denied/file locked [X] Wrong file size in directory [X] Wrong creation time in directory [ ] COM file is too large [X] Invalid start address [X] Invalid EXE header [X] Possibly damaged Summary report: [X] Create summary report Output file: AVWIN.ACT Maximum number of entries: 100 Where to search: [X] Memory [X] Boot record of selected drives [ ] Report unknown boot sectors [X] All files [ ] Program files Response in case of a detection: [X] Repair with prompt [ ] Repair without prompt [ ] Delete with prompt [ ] Delete without prompt [ ] Write in report file only [X] Acoustic alarm Response in case of destroyed files: [X] Delete with prompt [ ] Delete without prompt [ ] Ignore Response in case of destroyed files: [X] No change [ ] Current system time [ ] Correct date Drag&drop settings: [X] Scan subdirectories Profile settings: [X] Scan subdirectories Archive options [X] Search archive [X] Archive types to leave out 1000 1001 1002 Miscellaneous options: Temporary path: %TEMP% -> C:\DOCUME~1\BELDJE~1\LOCALS~1\Temp [X] Overwrite infected files [ ] Detect idle time [X] Allow interruptions of scan [X] Load AVWin®/NT Guard on System start General settings: [X] Save options on exiting AntiVir Priority: medium Drives: A: Floppy drive C: Hard disk D: Hard disk Q: CD-ROM R: CD-ROM Start of scan: vendredi 6 janvier 2006 22:13 Memory test OK Master boot record of hard disk HD0 OK Boot record of drive C: OK Boot record of drive D: OK Access denied! Error during file opening! Error code: 0x0002 C:\ WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 WARNING! Access error/file locked! C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery BDEProjector.zip ArchiveType: ZIP CarpeDiemVars.zip ArchiveType: ZIP NOTE! The whole archive is password protected CometCursors.zip ArchiveType: ZIP NOTE! The whole archive is password protected Comload.zip ArchiveType: ZIP CommonDialogs.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication1.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication2.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication3.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication4.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication5.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication6.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication7.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication8.zip ArchiveType: ZIP NOTE! The whole archive is password protected ConnectMFCApplication9.zip ArchiveType: ZIP NOTE! The whole archive is password protected Cydoor.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy1.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy2.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy3.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy4.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy5.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy6.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy7.zip ArchiveType: ZIP NOTE! The whole archive is password protected DivagoSurfairy8.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit1.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit10.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit11.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit12.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit13.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit14.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit2.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit3.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit4.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit5.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit6.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit7.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit8.zip ArchiveType: ZIP NOTE! The whole archive is password protected DSOExploit9.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb1.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb10.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb11.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb12.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb13.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb14.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb15.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb16.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb17.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb18.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb19.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb2.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb20.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb21.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb22.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb23.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb24.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb25.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb26.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb27.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb28.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb29.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb3.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb30.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb31.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb32.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb33.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb34.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb35.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb36.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb37.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb38.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb39.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb4.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb40.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb41.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb42.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb43.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb44.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb5.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb6.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb7.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb8.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWeb9.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts1.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts10.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts11.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts12.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts13.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts14.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts15.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts16.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts17.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts18.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts19.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts2.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts20.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts21.zip ArchiveType: ZIP FunWebProducts22.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts23.zip ArchiveType: ZIP FunWebProducts24.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts25.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts26.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts27.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts28.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts29.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts3.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts30.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts31.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts32.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts33.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts34.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts35.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts36.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts37.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts38.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts39.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts4.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts40.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts41.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts42.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts43.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts44.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts45.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts5.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts6.zip ArchiveType: ZIP FunWebProducts7.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts8.zip ArchiveType: ZIP NOTE! The whole archive is password protected FunWebProducts9.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc1.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc2.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc3.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc4.zip ArchiveType: ZIP NOTE! The whole archive is password protected Holistyc5.zip ArchiveType: ZIP NOTE! The whole archive is password protected ISearchTechSlotch.zip ArchiveType: ZIP NOTE! The whole archive is password protected MadoogaliAd.zip ArchiveType: ZIP NOTE! The whole archive is password protected MadoogaliAd1.zip ArchiveType: ZIP NOTE! The whole archive is password protected MadoogaliAd2.zip ArchiveType: ZIP NOTE! The whole archive is password protected MadoogaliAd3.zip ArchiveType: ZIP NOTE! The whole archive is password protected MadoogaliAd4.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent1.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent2.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent3.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent4.zip ArchiveType: ZIP NOTE! The whole archive is password protected MagicControlAgent5.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch1.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch10.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch100.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch101.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch102.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch103.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch104.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch105.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch106.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch107.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch108.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch109.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch11.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch110.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch111.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch112.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch113.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch114.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch115.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch116.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch117.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch118.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch119.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch12.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch120.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch121.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch122.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch123.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch124.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch125.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch126.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch127.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch128.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch129.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch13.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch130.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch131.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch132.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch133.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch134.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch135.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch136.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch137.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch138.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch139.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch14.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch140.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch141.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch142.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch143.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch144.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch145.zip ArchiveType: ZIP MyWebSearch146.zip ArchiveType: ZIP MyWebSearch147.zip ArchiveType: ZIP MyWebSearch148.zip ArchiveType: ZIP MyWebSearch149.zip ArchiveType: ZIP MyWebSearch15.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch150.zip ArchiveType: ZIP MyWebSearch151.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch152.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch153.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch154.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch155.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch156.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch157.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch158.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch159.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch16.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch160.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch161.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch162.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch163.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch164.zip ArchiveType: ZIP MyWebSearch165.zip ArchiveType: ZIP MyWebSearch166.zip ArchiveType: ZIP MyWebSearch167.zip ArchiveType: ZIP MyWebSearch168.zip ArchiveType: ZIP MyWebSearch169.zip ArchiveType: ZIP MyWebSearch17.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch170.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch171.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch172.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch173.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch174.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch175.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch176.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch177.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch178.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch179.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch18.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch180.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch181.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch182.zip ArchiveType: ZIP MyWebSearch183.zip ArchiveType: ZIP MyWebSearch184.zip ArchiveType: ZIP MyWebSearch185.zip ArchiveType: ZIP MyWebSearch186.zip ArchiveType: ZIP MyWebSearch187.zip ArchiveType: ZIP MyWebSearch188.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch189.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch19.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch190.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch191.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch192.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch193.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch194.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch195.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch196.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch197.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch198.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch199.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch2.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch20.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch21.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch22.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch23.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch24.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch25.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch26.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch27.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch28.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch29.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch3.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch30.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch31.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch32.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch33.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch34.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch35.zip ArchiveType: ZIP MyWebSearch36.zip ArchiveType: ZIP MyWebSearch37.zip ArchiveType: ZIP MyWebSearch38.zip ArchiveType: ZIP MyWebSearch39.zip ArchiveType: ZIP MyWebSearch4.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch40.zip ArchiveType: ZIP MyWebSearch41.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch42.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch43.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch44.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch45.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch46.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch47.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch48.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch49.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch5.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch50.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch51.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch52.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch53.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch54.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch55.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch56.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch57.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch58.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch59.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch6.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch60.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch61.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch62.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch63.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch64.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch65.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch66.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch67.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch68.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch69.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch7.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch70.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch71.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch72.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch73.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch74.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch75.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch76.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch77.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch78.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch79.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch8.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch80.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch81.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch82.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch83.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch84.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch85.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch86.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch87.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch88.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch89.zip ArchiveType: ZIP MyWebSearch9.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch90.zip ArchiveType: ZIP MyWebSearch91.zip ArchiveType: ZIP MyWebSearch92.zip ArchiveType: ZIP MyWebSearch93.zip ArchiveType: ZIP MyWebSearch94.zip ArchiveType: ZIP MyWebSearch95.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch96.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch97.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch98.zip ArchiveType: ZIP NOTE! The whole archive is password protected MyWebSearch99.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch1.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch2.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch3.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch4.zip ArchiveType: ZIP NOTE! The whole archive is password protected NavExcelWebsearch5.zip ArchiveType: ZIP NOTE! The whole archive is password protected nCase.zip ArchiveType: ZIP PromulGate.zip ArchiveType: ZIP NOTE! The whole archive is password protected TeknumUpdater.zip ArchiveType: ZIP NOTE! The whole archive is password protected TeknumUpdater1.zip ArchiveType: ZIP NOTE! The whole archive is password protected TeknumUpdater2.zip ArchiveType: ZIP NOTE! The whole archive is password protected Unknown.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer1.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer2.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer3.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer4.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer5.zip ArchiveType: ZIP webHancer6.zip ArchiveType: ZIP NOTE! The whole archive is password protected webHancer7.zip ArchiveType: ZIP NOTE! The whole archive is password protected WhazIt.zip ArchiveType: ZIP NOTE! The whole archive is password protected WhenUSaveNow.zip ArchiveType: ZIP NOTE! The whole archive is password protected WhenUSaveNow1.zip ArchiveType: ZIP NOTE! The whole archive is password protected WhenUSaveNow2.zip ArchiveType: ZIP C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads livetri.zip ArchiveType: ZIP Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\All Users\Documents\Ma musique\Échantillons de musique WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\All Users\Documents\Mes images WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\All Users\Documents\Mes images\photo1 WARNING! Access error/file locked! C:\Documents and Settings\beldjelti ntuser.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\beldjelti\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\1 an de sonia WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\2005_0422photo4 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\2005_0626repasbea WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\2005_0709Image WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Incoming WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Ma musique WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Ma musique\emule WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Ma musique\emule\Incoming WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Ma musique\emule\webserver WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes fichiers reçus WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2004_0101photo1 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2004_0102photo2 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2004_0108photo3 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0412famille WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0422photo4 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0425ricardo WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0425ricardo\2005_0423 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0425ricardo\2005_0424 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0425ricardo\2005_0425 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0502sonia WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0504catachan WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0504catachan\42792487.tmp\42792487.tmp WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_05132005 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0514christiane WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0523hafida WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0609sonia WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0623ricardo WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0626repasbea WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0627mes1an WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0706repasricardoetsue WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0718vacances2005 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0827gerer WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0905mariagesuericardo WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_0923sept WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2005_123101012006 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\2006_010201012006 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\had+sonia WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\photo st maur WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\Mes images\vacances 2005 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\My Albums WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Mes documents\planning WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\beldjelti\Shared WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\farid\Mes documents\Mes vidéos WARNING! Access error/file locked! C:\Documents and Settings\LocalService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService NTUSER.DAT Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ntuser.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows UsrClass.dat Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! UsrClass.dat.LOG Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\steven\Bureau\steven WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\steven\Mes documents\steven WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Documents and Settings\steven\Mes documents\steven\2005_0410Image WARNING! Access error/file locked! C:\DRIVERS\MCDBF\SOURCE1 OTHER.EXE ArchiveType: ARJ SFX (self extracting) NOTE! The whole archive is password protected TSADDON.EXE ArchiveType: ARJ SFX (self extracting) --> UNISHHS.ARJ ArchiveType: ARJ NOTE! The whole archive is password protected Access denied! Error during file opening! Error code: 0x0002 C:\My Shared Folder WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\RECYCLER\S-1-5-21-4210259494-357464061-2299825339-1005\Dc8 WARNING! Access error/file locked! Access denied! Error during file opening! Error code: 0x0002 C:\Seven Kingdoms II\LobbyRes WARNING! Access error/file locked! Error! Could not change directory: System Volume Information C:\WINDOWS\$NtUninstallKB828741$ catsrv.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! catsrvut.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! clbcatex.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! clbcatq.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! colbact.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! comadmin.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! comrepl.exe Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! comsvcs.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! comuid.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! es.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! msdtcprx.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! msdtctm.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! msdtcuiu.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! mtxclu.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! mtxoci.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ole32.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! rpcrt4.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! rpcss.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! txflog.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! C:\WINDOWS\$NtUninstallKB835732$ callcont.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! gdi32.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! h323.tsp Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! h323msp.dll Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! helpctr.exe Access denied! Error during file opening! Error code: 0x000D WARNING! Access error/file locked! ipnathlp.dll Access denied! Error during fil
  22. coucou je ne doute pas de tes competences ............ donc apriori j ai fait tte les manipulations . au depart j avais un probleme avec spybot avec virus magiccontol agent que je n arrivai pas a enlever et puis on a trouve beaucoup de trucs pas bon pr pc alors j ai fait vos procedures ................ je rescane pr voir sinon j ai antivir qui me signale virus dont je refuse l acces et au demarage j ai un message de gestionnaire des taches mais me rapelle pus de quoi ca parle tu crois que je devrai enlever la ligne suivante O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min voici dernier rapport....... Scan saved at 21:42:17, on 06/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Apps\ActivBoard\nhksrv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\PROGRA~1\MSNMES~1\msnmsgr.exe C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\hidjaker\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
  23. re je n ai pas trouve la ligne sur service: adsl autoconnect elle n y es pas ?????? et apres tout ca je me serai debarasser de ts les virus et le magic control ? comme j ai deja dit j y connait rien et j espere que je ne vais pas tout deregler ds cette ordi! j oubliai avant j avais numericable comme acces adsl maintenant c es free.....a+ mais la ligne que tiu dit y a bien ecrit avg quand meme c es bizarre..........
  24. ds ajout suppression il n ya plus avg je l ai supprimer auparavant il me reste donc que antivir . je reessaye ds mes ajout suppression pr revoir mais.......... Scan saved at 12:58:58, on 06/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Apps\ActivBoard\MMKeybd.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\Apps\ActivBoard\TrayMon.exe C:\Apps\ActivBoard\OSD.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\drwtsn32.exe C:\Program Files\hidjaker\HijackThis.exe C:\WINDOWS\system32\drwtsn32.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = htt:\\www.numericable.fr R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B6A369B5-ADB7-4611-8493-72254EC4EED5}: NameServer = 217.27.32.5,213.228.0.168 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe et la est ce que c es bon.........
  25. j ai revu jai fait ce que tu m a dit mais est ce cette ligne que je devais cocher O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min si c es le cas tu ne me l a pas mis ds toute la liste a cocher mais je peut la cocher si c es bien celle la qu il faut virer ??????
×
×
  • Créer...