Aller au contenu

Andante

Membres
  • Compteur de contenus

    19
  • Inscription

  • Dernière visite

Tout ce qui a été posté par Andante

  1. Bonsoir, De retour après une semaine de boulot... j'ai pu vérifier que TOUT fonctionne parfaitement sur mon PC . Merci les gars ! Si je peux abuser, vous m'aviez laissé entendre que vous auriez quelques conseils à me donner pour protéger mon ordi. Je suis preneur si vous avez encore un peu de temps à me consacrer.... Cordialement
  2. Très tard... et je me lève dans quatre heures ! Je pars jusqu'à vendredi soir (le boulot c'est le boulot !). Je prendrai volontiers connaissance de vos conseils à mon retour vendredi soir . Encore merci et bonne nuit !
  3. En effet c'était bcp plus rapide cette fois. Voici donc le rapport smit file en version 2.8 smitRem © log file version 2.8 by noahdfear Microsoft Windows XP [version 5.1.2600] Running from C:\Documents and Settings\Philippe\Bureau\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 756 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! Ca a l'air bon maintenant, non ??? Merci à vous deux !
  4. Tout à l'air de fonctionner .... Un GRAND MERCI à toi Charles !!!!
  5. A première vue tout fonctionne correctement.... Merci infiniment ... Peut-on être certain que la saloperie est vraiment éradiquée ?
  6. Voici le fichier smitfile : smitRem log file version 2.2 by noahdfear ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run Files Present ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Post-run Files Present ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Wininet.dll ~~~ CLEAN!
  7. J'ai déja téléchargé celle indiquée par Charles... Dans la fenêtre Ms-Dos, "on" m'a averti que le nettoyage était estimé à plus de trois heures (!) ... et en effet ça ne semble pas très rapide. En fait, ça a même l'air de ne plus avancer du tout....
  8. Voici le rapport de reg search : REGEDIT4 ; Registry Search by Bobbi Flekman © 2005 ; Version: 1.0.2.4 ; Results at 30/01/2006 22:17:02 for strings: ; 'spyaxe' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0] @="SpyAxe 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0\0\win32] @="C:\\Program Files\\SpyAxe\\spyaxe.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0\HELPDIR] @="C:\\Program Files\\SpyAxe\\" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-21-1170410397-1661736451-2730170407-1005_Classes\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.biz\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.com\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxe.net\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyaxeupdate.com] ; End Of The Log...
  9. Les alertes Spy axe ont disparues... Le système n'est pas très stable : ça fait deux fois qu'il plante, mais moins rapidement qu'avant, ce qui me laisse de faire quelques manip en mode normal... En revanche, je n'arrive pas à réinstaller AVG Free : l'installation semble se dérouler normalement jusqu'à ce qu'un message apparaisse : an error occured , etc..." Le détail de l'erreur est le suivant : "Action failded for file avg7rsw.sys: starting service...Le fichier spécifié est introuvable". Bref on progresse mais je n'ai plus d'antivirus et un système assez instable....
  10. Dernière news : l'abonnement Norton ayant expiré, je remts AVG comme anti virus et vire Norton. Désolé pour tous ces changements. Je reste en attente de votre aide .... Cordialement Andante
  11. De retour.... Suite à ton dernier message, j'ai viré tous les programmes à la c... du genre shareaza, kazza, etc. J'en ai profité pour faire du tri et du ménage dans mes fichiers. Suivant le lien indiqué sur les dangers des logiciels P2P, j'ai suivi également le lien présent sur cette page sur la désinfection du PC et ai suivi les conseils (ATF cleaner, Spybot, Antivir et Autorun + nettoyages divers), le tout en mode sans échec puisque mon PC ne tient toujours pas plus de 10 secondes en mode normal. Voila. J'espère que cela n'aura pas perturbé le résultat des rapports déja postés... Je reste en attente de conseils pour la suite de la procédure (à ce stade, rien n'y fait : j'ai toujours mon ordi qui plante au bout de 10 secondes et toujours les messages d'alerte même en mode sans échec). En attente de te lire... Pour les antivirus, j'ai viré antivir après utilisation. Norton ne veux pas s'enlever en mode sans échec (le seul que j'arrive à tenir). Je vais voir si j'arrive à virer AVG et à garder Norton... Voilà les dernières nouvelles : AVG a été viré. J'ai réussi à redémarrer en mode normal et ça à l'air de tenir.... Voici le rapport Hitjackthis fait à l'instant en mode normal : Logfile of HijackThis v1.99.1 Scan saved at 21:15:35, on 30/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\PROGRA~1\NORTON~2\NORTON~1\GHOSTS~2.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\9Telecom\modem_ADSL_USB_Comtrend_CT-350\dslmon.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe O4 - Global Startup: DSLMON-9Online.LNK = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddLink.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddList.html O9 - Extra button: (no name) - AutorunsDisabled - (no file) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://streamplug.com/StreamPlug/SP.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/playe...5/Installer.exe O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\ O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\GHOSTS~2.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  12. OK, OK j'enlève tous ces programmes de m... A ce soir et encore merci ! Andante
  13. OK, le dossier preftech a été vidé et la corbeille vidée ... Dois-je virer kazaa, shareaza tout de suite ???
  14. Salut Charles Ingals, Merci de ta rapidité. Voici le fichier both.log : Logfile of HijackThis v1.99.1 Scan saved at 13:23:25, on 30/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cmd.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\system32\ping.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe O4 - Global Startup: DSLMON-9Online.LNK = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddLink.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Fichiers communs\justDo\IECatcher.DLL/FlashCatcher.htm O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddList.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://streamplug.com/StreamPlug/SP.cab O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.ofoto.fr/downloads/hmpr/HMPR_WI..._1/axhomepr.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/playe...5/Installer.exe O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z (file missing) O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\GHOSTS~2.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iexplore.exe doesn't exist HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe ----------------------- ----------------------- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG Shell Extension] @="{1E2CDF40-419B-11D2-A5A1-002018648BA7}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension] @="{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido] @="{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files] @="{750fdf0e-2a26-11d1-a3ea-080036587f03}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With] @="{09799AFB-AD67-11d1-ABCD-00C04FC30936}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu] @="{A470F8CF-A1E8-4f65-8335-227475AA5C46}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\PowerArchiver] @="{d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\StuffIt Compress Menu] @="{3FBFD0B0-EB46-4797-9101-615610E87DA6}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu] @="{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}] @="Épingle du menu Démarrer" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" "{D81E2FC4-B0A2-11D3-21AC-07C04C21A18A}"="Replay for WindowsXP" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "PinnacleDriverCheck"="C:\\WINDOWS\\System32\\PSDrvCheck.exe" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe" "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\\Program Files\\Google\\Gmail Notifier\\G001-1.0.25.0\\gnotify.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe" "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\ 65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\not active] "CARPService"="carpserv.exe" "OEM-Reset"="" "Optimize"="" "LVCOMS"="C:\\Program Files\\Fichiers communs\\Logitech\\QCDriver3\\LVCOMS.EXE" "LogitechGalleryRepair"="C:\\Program Files\\Logitech\\ImageStudio\\ISStart.exe" "LogitechImageStudioTray"="C:\\Program Files\\Logitech\\ImageStudio\\LogiTray.exe" "adiras"="adiras.exe" "iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe" "TotalRecorderScheduler"="\"C:\\Program Files\\HighCriteria\\TotalRecorder\\TotRecSched.exe\"" "GhostStartTrayApp"="C:\\Program Files\\Norton SystemWorks\\Norton Ghost\\GhostStartTrayApp.exe" "MMTray2k"="MMTray2k.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot" "PinnacleDriverCheck"="C:\\WINDOWS\\System32\\PSDrvCheck.exe" "Norton"="C:\\Program Files\\ASUS\\WLAN Card Utilities\\NorExec.exe" "ccRegVfy"="\"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccRegVfy.exe\"" "ccApp"="\"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe\"" "MessengerPlus3"="\"C:\\Program Files\\Messenger Plus! 3\\MsgPlus.exe\"" "WinampAgent"="\"C:\\Program Files\\Winamp3\\winampa.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Ashampoo PopUpBlocker"="C:\\PROGRA~1\\Ashampoo\\ASHAMP~1\\PopUpKiller.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\not active] "CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe" @="" "ATI Launchpad"="\"C:\\Program Files\\ATI Multimedia\\main\\launchpd.exe\"" "ATI Remote Control"="C:\\Program Files\\ATI Multimedia\\RemCtrl\\ATIRW.exe" "InstantTray"="C:\\Program Files\\Pinnacle\\Shared Files\\InstantCDDVD\\PCLETray.exe" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] Scheduled Tasks Folder Contents * C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur.job C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\Symantec NetDetect.job
  15. OK, j'ai fait tout ce qui a été demandé (sauf de supprimer 1 des deux antivrus : à ma connaissance je n'en ai qu'un seul - AVG - et il ne reste de Norton que les outils de diagnostic mais pas l'antivirus). Voici le fichier log généré par sysclean (eefectivement il fallait être patient). Pour info, j'ai toujours les fenêtres intempestives d'alerte... Et le PC plante toujours au bout de quelques secondes en mode normal. /--------------------------------------------------------------\ | Trend Micro Sysclean Package | | Copyright 2002, Trend Micro, Inc. | | http://www.trendmicro.com | \--------------------------------------------------------------/ 2006-01-30, 01:23:27, Auto-clean mode specified. 2006-01-30, 01:23:27, Running scanner "C:\Program Files\Sysclean Package\TSC.BIN"... 2006-01-30, 01:25:04, Scanner "C:\Program Files\Sysclean Package\TSC.BIN" has finished running. 2006-01-30, 01:25:04, TSC Log: Damage Cleanup Engine (DCE) 3.98(Build 1012) Windows XP(Build 2600: Service Pack 2) Start time : lun. janv. 30 2006 01:23:27 Load Damage Cleanup Template (DCT) "C:\Program Files\Sysclean Package\tsc.ptn" (version 700) [success] Complete time : lun. janv. 30 2006 01:25:04 Execute pattern count(4688), Virus found count(0), Virus clean count(0), Clean failed count(0) 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\NTUSER.DAT": Accès refusé. 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\ntuser.dat.LOG": Accès refusé. 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Accès refusé. 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Accès refusé. 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\Philippe\NTUSER.DAT": Accès refusé. 2006-01-30, 01:26:41, An error occurred while scanning file "C:\Documents and Settings\Philippe\ntuser.dat.LOG": Accès refusé. 2006-01-30, 07:16:06, An error occurred while scanning file "C:\Documents and Settings\Philippe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat": Accès refusé. 2006-01-30, 07:16:06, An error occurred while scanning file "C:\Documents and Settings\Philippe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000368.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000369.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000370.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000371.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000372.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000373.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000374.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000375.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000376.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000377.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000378.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000379.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000380.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000381.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000382.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000383.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000384.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000385.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000386.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000387.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000388.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000389.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000390.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000391.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000392.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000393.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000394.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000395.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000396.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000397.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000398.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000399.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000400.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000401.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000402.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000403.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000404.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000405.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000406.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000407.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000408.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000409.PF": Accès refusé. 2006-01-30, 08:02:19, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000410.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000411.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000412.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000413.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000414.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000415.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000416.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000417.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000418.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000419.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000420.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000421.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000422.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000423.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000424.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000425.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000426.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000427.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000428.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000429.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000430.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000431.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000432.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000433.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000434.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000435.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000436.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000437.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000438.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000439.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000440.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000441.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000442.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000443.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000444.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000445.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000446.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000447.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000448.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000449.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000450.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000451.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000452.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000453.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000454.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000455.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000456.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000457.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000458.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000459.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000460.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000461.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000462.PF": Accès refusé. 2006-01-30, 08:02:20, Could not set file for reading on "C:\RECYCLER\NPROTECT\00000463.PF": Accès refusé. 2006-01-30, 08:03:47, An error was detected on "C:\System Volume Information\*.*": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB824141$\user32.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB824141$\win32k.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\hh.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\html32.cnv": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\itss.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\locator.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\magnify.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\narrator.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\newdev.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\ole32.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\osk.exe": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\shell32.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\srv.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\sysmain.sdb": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\user32.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\win32k.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\ndis.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\netshell.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB826942$\xpsp2res.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll": Accès refusé. 2006-01-30, 08:08:15, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\dao360.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\expsrv.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msexch40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msexcl40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjet40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjetol1.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjetoledb40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjint40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjter40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msjtes40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msltus40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\mspbde40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msrd2x40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msrd3x40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msrepl40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\mstext40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\mswdat10.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\mswstr10.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\msxbde40.dll": Accès refusé. 2006-01-30, 08:08:18, Could not set file for reading on "C:\WINDOWS\$NtUninstallKB829558$\vbajet32.dll": Accès refusé. 2006-01-30, 08:09:35, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx": Accès refusé. 2006-01-30, 08:09:35, Could not set file for reading on "C:\WINDOWS\$NtUninstallQ828026$\wmp.dll": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ACDSEE6.EXE-102B22BB.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ACROBAT.EXE-33FD5B8C.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AD-AWARE.EXE-3262F7A9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AOM.EXE-3600A9D7.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AU_.EXE-13B63E46.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3038B75E.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGINET.EXE-3B0744C3.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-00A2F684.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGW.EXE-011FD837.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGWB.DAT-01D5CE53.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\AVSVIDEOCONVERTER3.EXE-16F21053.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\BSPLAY.EXE-2673C09E.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\CALC.EXE-02CD573A.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\CRACK.EXE-1F4BD1F4.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DBLOCALSERVER.EXE-30CBAA24.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DRWTSN32.EXE-2B4B52AC.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\DXOLE32.EXE-1FB557AC.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ECODEC-V4.148.EXE-01A80534.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ECODEC.EXE-05062B00.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ERROR DOCTOR V 1.2 PATCH.EXE-2E313A04.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ERRORDOCTOR.EXE-0D488772.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ERRORDOCTORSETUP.EXE-0E2EDB8B.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\EWIDO-SETUP.EXE-39614DAB.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\EWIDOCTRL.EXE-0EEA53F9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\EWIDOGUARD.EXE-191211F9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\EXCEL.EXE-2C971FD7.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\FIND.EXE-0EC32F1E.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\FINDSTR.EXE-0CA6274B.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\FIREFOX SETUP 1.5.EXE-05606FBA.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\FIREFOX.EXE-28641590.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\GETPOPUPINFO.EXE-22F2D0C9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\IEDW.EXE-1880380E.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\IS-A6NPQ.TMP-059D884A.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\KAZAALITE.KPP-07844056.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\KLRUN.EXE-3ACB424A.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\KPP.EXE-375CBF39.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LD442A.TMP-308BD552.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LD44B6.TMP-3710656F.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LD44D5.TMP-0BDA9658.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LD4504.TMP-116DFF7B.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LD4581.TMP-10CF9528.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\METEO-LIVE.EXE-3735DC90.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MMC.EXE-398DCF39.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MP4CAM2AVI.EXE-23FDC1B4.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSCONFIG.EXE-35E4DAE9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSCORNET.EXE-07F16FE2.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIMN.EXE-38BA891D.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSMSGS.EXE-2B6052DE.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSNMSGR.EXE-366A1A81.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\MSSEARCHNET.EXE-0AFC02C2.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NAVW32.EXE-24F56911.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NETTRANSPORT.EXE-0B645831.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\NVCTRL.EXE-06D3483B.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\PAYTIME.EXE-326BBEE6.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\PI.EXE-33A72C5C.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\PICTUREACELITE.EXE-2F53AD88.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\POWERARC.EXE-37FF1F0A.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\RASAUTOU.EXE-18B88A68.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-147710F4.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-18044F5D.pf": Accès refusé. 2006-01-30, 08:15:13, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-1A00B500.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26111652.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26C6C6B5.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-311943EE.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-414A99C9.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-4489B61B.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SA9B.EXE-00DBA237.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SA_SETUP.EXE-1515AA84.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SECURITYSUITE.EXE-278F473B.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-24DD2D74.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SHAREAZA.EXE-2D2D5468.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SPIDER.EXE-2D998CA6.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYAXE.EXE-1E39CDF6.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYBOTSD.EXE-1344276B.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYSWEEPER.EXE-15D18B6A.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYWARESTRIKE.EXE-09307CA4.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\SSFISETUP1_1845723986.EXE-196074DB.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\TOOL1.EXE-0CD23B85.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\TOOL2.EXE-2CF952BB.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\TOOL3.EXE-22058AF7.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\UNINS000.EXE-050D0229.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\UNINS000.EXE-32AD7C65.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\UNINST.EXE-029DA78C.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\UNINST.EXE-2B0C60B8.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WINHLP32.EXE-2C18E975.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-29F5CB89.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WRSSSDK.EXE-053DAB7A.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Accès refusé. 2006-01-30, 08:15:14, Could not set file for reading on "C:\WINDOWS\Prefetch\_IU14D2N.TMP-282BFC1A.pf": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Accès refusé. 2006-01-30, 08:19:37, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Accès refusé. 2006-01-30, 08:24:51, Running scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN"... 2006-01-30, 09:19:58, Files Detected: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 08:24:52 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Program Files\Sysclean Package 63459 files have been read. 63459 files have been checked. 52147 files have been scanned. 94344 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:19:58 ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:19:58, Files Clean: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 08:24:52 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Program Files\Sysclean Package 63459 files have been read. 63459 files have been checked. 52147 files have been scanned. 94344 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:19:58 54 minutes 59 seconds (3298.72 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:19:58, Clean Fail: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 08:24:52 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Program Files\Sysclean Package 63459 files have been read. 63459 files have been checked. 52147 files have been scanned. 94344 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:19:58 54 minutes 59 seconds (3298.72 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:19:58, Scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN" has finished running. 2006-01-30, 09:20:00, Running scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN"... 2006-01-30, 09:22:47, Files Detected: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 09:20:00 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Program Files\Sysclean Package 977 files have been read. 977 files have been checked. 700 files have been scanned. 2286 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:22:47 ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:22:47, Files Clean: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 09:20:00 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Program Files\Sysclean Package 977 files have been read. 977 files have been checked. 700 files have been scanned. 2286 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:22:47 2 minutes 40 seconds (159.50 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:22:47, Clean Fail: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 09:20:00 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=C:\Program Files\Sysclean Package 977 files have been read. 977 files have been checked. 700 files have been scanned. 2286 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 09:22:47 2 minutes 40 seconds (159.50 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 09:22:47, Scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN" has finished running. 2006-01-30, 10:08:27, Running scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN"... 2006-01-30, 10:15:49, Files Detected: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 10:08:27 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 I:\*.* /P=C:\Program Files\Sysclean Package 15468 files have been read. 15468 files have been checked. 8862 files have been scanned. 17057 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 10:15:49 ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 10:15:49, Files Clean: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 10:08:27 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 I:\*.* /P=C:\Program Files\Sysclean Package 15468 files have been read. 15468 files have been checked. 8862 files have been scanned. 17057 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 10:15:49 7 minutes 15 seconds (435.00 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 10:15:49, Clean Fail: Copyright © 1990 - 2004 Trend Micro Inc. Report Date : 1/30/2006 10:08:27 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Virus Pattern Version : 182 (121065 Patterns) (2006/01/29) (318219) Command Line: C:\Program Files\Sysclean Package\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 I:\*.* /P=C:\Program Files\Sysclean Package 15468 files have been read. 15468 files have been checked. 8862 files have been scanned. 17057 files have been scanned. (including files in archived) 0 files containing viruses. Found 0 viruses totally. Maybe 0 viruses totally. Stop At : 1/30/2006 10:15:49 7 minutes 15 seconds (435.00 seconds) has elapsed. ---------*---------*---------*---------*---------*---------*---------*---------* 2006-01-30, 10:15:49, Scanner "C:\Program Files\Sysclean Package\VSCANTM.BIN" has finished running.
  16. Le voici : StartupList report, 30/01/2006, 00:39:49 StartupList version: 1.52.2 Started from : C:\Program Files\HijackThis\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options * Including empty and uninteresting sections * Showing rarely important sections ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\HijackThis\HijackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\Démarrage] Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE Shell folders AltStartup: *Folder not found* User shell folders Startup: *Folder not found* User shell folders AltStartup: *Folder not found* Shell folders Common Startup: [C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage] Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe DSLMON-9Online.LNK = ? Shell folders Common AltStartup: *Folder not found* User shell folders Common Startup: *Folder not found* User shell folders Alternate Common Startup: *Folder not found* -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] *Registry value not found* [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run SoundMan = SOUNDMAN.EXE ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe {0228e555-4f9c-4e35-a3ec-b109a192b4c2} = C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe" Zone Labs Client = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Ashampoo PopUpBlocker = C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run MMTray2k = MMTray2k.exe -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run [not active] CARPService = carpserv.exe OEM-Reset = Optimize = LVCOMS = C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE LogitechGalleryRepair = C:\Program Files\Logitech\ImageStudio\ISStart.exe LogitechImageStudioTray = C:\Program Files\Logitech\ImageStudio\LogiTray.exe adiras = adiras.exe iTunesHelper = C:\Program Files\iTunes\iTunesHelper.exe TotalRecorderScheduler = "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe" GhostStartTrayApp = C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe MMTray2k = MMTray2k.exe SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime TkBellExe = "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe Norton = C:\Program Files\ASUS\WLAN Card Utilities\NorExec.exe ccRegVfy = "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe" ccApp = "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" MessengerPlus3 = "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" WinampAgent = "C:\Program Files\Winamp3\winampa.exe" [OptionalComponents] *No values found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [not active] CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe = ATI Launchpad = "C:\Program Files\ATI Multimedia\main\launchpd.exe" ATI Remote Control = C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe InstantTray = C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- File association entry for .EXE: HKEY_CLASSES_ROOT\exefile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .COM: HKEY_CLASSES_ROOT\comfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .BAT: HKEY_CLASSES_ROOT\batfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .PIF: HKEY_CLASSES_ROOT\piffile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\scrfile\shell\open\command (Default) = "%1" /S -------------------------------------------------- File association entry for .HTA: HKEY_CLASSES_ROOT\htafile\shell\open\command (Default) = C:\WINDOWS\System32\mshta.exe "%1" %* -------------------------------------------------- File association entry for .TXT: HKEY_CLASSES_ROOT\txtfile\shell\open\command (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT [{5945c046-1e7d-11d1-bc44-00c04fd912be}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub [{7790769C-0471-11d2-AF11-00C04FA35D02}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = %SystemRoot%\system32\ie4uinit.exe [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] * StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install -------------------------------------------------- Enumerating ICQ Agent Autostart apps: HKCU\Software\Mirabilis\ICQ\Agent\Apps *Registry key not found* -------------------------------------------------- Load/Run keys from C:\WINDOWS\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs= -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\WINDOWS\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: HIDDEN! .shb: HIDDEN! .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Verifying REGEDIT.EXE integrity: - Regedit.exe found in C:\WINDOWS - .reg open command is normal (regedit.exe %1) - Regedit.exe has no CompanyName property! It is either missing or named something else. - Regedit.exe has no OriginalFilename property! It is either missing or named something else. - Regedit.exe has no FileDescription property! It is either missing or named something else. Registry check failed! -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - (no file) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} -------------------------------------------------- Enumerating Task Scheduler jobs: Norton AntiVirus - Analyser mon ordinateur.job Norton SystemWorks One Button Checkup.job Symantec NetDetect.job -------------------------------------------------- Enumerating Download Program Files: [fdjeux] CODEBASE = https://www.fdjeux.net/classes/fdjeux.cab OSD = C:\WINDOWS\Downloaded Program Files\fdjeux.osd [Microsoft XML Parser for Java] OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd [teleir_cert] CODEBASE = https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab OSD = C:\WINDOWS\Downloaded Program Files\teleir_cert.osd [shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll CODEBASE = http://fpdownload.macromedia.com/get/shock...director/sw.cab [streamPlug Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\StreamPlug.dll CODEBASE = http://streamplug.com/StreamPlug/SP.cab [{33564D57-0000-0010-8000-00AA00389B71}] CODEBASE = http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab [HomePrintingCtrl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\axhomepr.dll CODEBASE = http://www.ofoto.fr/downloads/hmpr/HMPR_WI..._1/axhomepr.cab [Java Plug-in 1.4.2_04] InProcServer32 = C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll CODEBASE = http://java.sun.com/products/plugin/autodl...indows-i586.cab [{9F1C11AA-197B-4942-BA54-47A8489BB47F}] CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/...8027.3982175926 [Virtools WebPlayer Class] InProcServer32 = C:\Program Files\Virtools Web Player 2.5\WebPlayer.ocx CODEBASE = http://player.virtools.com/downloads/playe...5/Installer.exe [Java Plug-in 1.4.2_04] InProcServer32 = C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll CODEBASE = http://java.sun.com/products/plugin/autodl...indows-i586.cab [shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx CODEBASE = http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\WINDOWS\System32\mswsock.dll NameSpace #2: C:\WINDOWS\System32\winrnr.dll NameSpace #3: C:\WINDOWS\System32\mswsock.dll Protocol #1: C:\WINDOWS\system32\mswsock.dll Protocol #2: C:\WINDOWS\system32\mswsock.dll Protocol #3: C:\WINDOWS\system32\mswsock.dll Protocol #4: C:\WINDOWS\system32\rsvpsp.dll Protocol #5: C:\WINDOWS\system32\rsvpsp.dll Protocol #6: C:\WINDOWS\system32\mswsock.dll Protocol #7: C:\WINDOWS\system32\mswsock.dll Protocol #8: C:\WINDOWS\system32\mswsock.dll Protocol #9: C:\WINDOWS\system32\mswsock.dll Protocol #10: C:\WINDOWS\system32\mswsock.dll Protocol #11: C:\WINDOWS\system32\mswsock.dll Protocol #12: C:\WINDOWS\system32\mswsock.dll Protocol #13: C:\WINDOWS\system32\mswsock.dll Protocol #14: C:\WINDOWS\system32\mswsock.dll Protocol #15: C:\WINDOWS\system32\mswsock.dll Protocol #16: C:\WINDOWS\system32\mswsock.dll Protocol #17: C:\WINDOWS\system32\mswsock.dll Protocol #18: C:\WINDOWS\system32\mswsock.dll Protocol #19: C:\WINDOWS\system32\mswsock.dll Protocol #20: C:\WINDOWS\system32\mswsock.dll Protocol #21: C:\WINDOWS\system32\mswsock.dll Protocol #22: C:\WINDOWS\system32\mswsock.dll Protocol #23: C:\WINDOWS\system32\mswsock.dll Protocol #24: C:\WINDOWS\system32\mswsock.dll Protocol #25: C:\WINDOWS\system32\mswsock.dll -------------------------------------------------- Enumerating Windows NT/2000/XP services Pilote ACPI Microsoft: System32\DRIVERS\ACPI.sys (system) General Purpose USB Driver (adildr.sys): System32\Drivers\adildr.sys (autostart) USB ADSL WAN Adapter: System32\DRIVERS\adiusbaw.sys (manual start) ADSLAutoconnect: "C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z (manual start) Suppresseur d'écho acoustique (Noyau Microsoft): system32\drivers\aec.sys (manual start) Environnement de prise en charge de réseau AFD: \SystemRoot\System32\drivers\afd.sys (system) Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start) Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start) Avertissement: %SystemRoot%\System32\svchost.exe -k LocalService (disabled) Service de la passerelle de la couche Application: %SystemRoot%\System32\alg.exe (manual start) Pilote de processeur AMD Athlon64: System32\DRIVERS\AmdK8.sys (system) Gestion d'applications: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Protocole client ARP 1394: System32\DRIVERS\arp1394.sys (manual start) ASAPIW2K: System32\Drivers\ASAPIW2K.sys (manual start) ASNDIS5 Protocol Driver: \??\C:\WINDOWS\System32\ASNDIS5.SYS (manual start) Pilote de média asynchrone RAS: System32\DRIVERS\asyncmac.sys (manual start) Contrôleur de disque dur IDE/ESDI standard: System32\DRIVERS\atapi.sys (system) Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart) ATI Smart: C:\WINDOWS\system32\ati2sgag.exe (autostart) ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start) ATI WDM Rage Theater Video: System32\DRIVERS\atinrvxx.sys (manual start) ATI WDM TV Tuner: System32\DRIVERS\atintuxx.sys (autostart) ATI WDM Rage Theater Audio: System32\DRIVERS\atinraxx.sys (manual start) ATI WDM TV Audio Crossbar: System32\DRIVERS\atinxsxx.sys (autostart) Protocole client ATM ARP: System32\DRIVERS\atmarpc.sys (manual start) Audio Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote audio Stub: System32\DRIVERS\audstub.sys (manual start) AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart) AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system) AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system) AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system) AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart) AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart) Service de transfert intelligent en arrière-plan: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pont MAC: System32\DRIVERS\bridge.sys (manual start) Miniport de pont MAC: System32\DRIVERS\bridge.sys (manual start) Explorateur d'ordinateur: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Décodeur sous-titre fermé: System32\DRIVERS\CCDECODE.sys (manual start) Symantec Event Manager: "C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe" (autostart) Symantec Password Validation Service: "C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe" (manual start) Cdrdrv: System32\Drivers\Cdrdrv.sys (manual start) Pilote de CD-ROM: System32\DRIVERS\cdrom.sys (system) Service d'indexation: %SystemRoot%\system32\cisvc.exe (manual start) Gestionnaire de l'Album: %SystemRoot%\system32\clipsrv.exe (disabled) Application système COM+: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start) Services de cryptographie: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Lanceur de processus serveur DCOM: %SystemRoot%\system32\svchost -k DcomLaunch (autostart) Client DHCP: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote de disque: System32\DRIVERS\disk.sys (system) Service d'administration du Gestionnaire de disque logique: %SystemRoot%\System32\dmadmin.exe /com (manual start) dmboot: System32\drivers\dmboot.sys (disabled) dmio: System32\drivers\dmio.sys (disabled) dmload: System32\drivers\dmload.sys (disabled) Gestionnaire de disque logique: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Synthétiseur DLS du noyau Microsoft: system32\drivers\DMusic.sys (manual start) Client DNS: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) Filtre de décodeur DRM (Noyau Microsoft): system32\drivers\drmkaud.sys (manual start) Service de rapport d'erreurs: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Journal des événements: %SystemRoot%\system32\services.exe (autostart) Système d'événements de COM+: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start) ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart) ewido security suite driver: \??\C:\Program Files\ewido anti-malware\guard.sys (system) ewido security suite guard: C:\Program Files\ewido anti-malware\ewidoguard.exe (autostart) Compatibilité avec le Changement rapide d'utilisateur: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote de contrôleur de lecteur de disquettes: System32\DRIVERS\fdc.sys (manual start) Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet: System32\DRIVERS\fetnd5.sys (manual start) VIA Rhine Family Fast Ethernet Adapter Driver Service: System32\DRIVERS\fetnd5b.sys (manual start) Pilote de lecteur de disquettes: System32\DRIVERS\flpydisk.sys (manual start) FltMgr: system32\drivers\fltmgr.sys (system) Pilote du Gestionnaire de volume: System32\DRIVERS\ftdisk.sys (system) GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start) GhostStartService: C:\PROGRA~1\NORTON~2\NORTON~1\GHOSTS~2.EXE (autostart) GhostPciScanner: \??\C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys (system) Classificateur de paquets générique: System32\DRIVERS\msgpc.sys (manual start) Aide et support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Pilote de classe HID Microsoft: System32\DRIVERS\hidusb.sys (manual start) HSFHWBS2: System32\DRIVERS\HSFHWBS2.sys (manual start) HSF_DP: System32\DRIVERS\HSF_DP.sys (manual start) HTTP: System32\Drivers\HTTP.sys (manual start) HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start) Pilote pour clavier i8042 et souris sur port PS/2: System32\DRIVERS\i8042prt.sys (system) Pilote de filtre de gravure CD: System32\DRIVERS\imapi.sys (system) Service COM de gravage de CD IMAPI: C:\WINDOWS\System32\imapi.exe (manual start) Pilote du pare-feu Windows IPv6: system32\drivers\ip6fw.sys (manual start) Pilote de filtre de trafic IP: System32\DRIVERS\ipfltdrv.sys (manual start) Pilote de tunnelage IP dans IP: System32\DRIVERS\ipinip.sys (manual start) Traducteur d'adresses réseau IP: System32\DRIVERS\ipnat.sys (manual start) iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start) Pilote IPSEC: System32\DRIVERS\ipsec.sys (system) Service énumérateur IR: System32\DRIVERS\irenum.sys (manual start) Pilote de bus Plug-and-Play ISA/EISA: System32\DRIVERS\isapnp.sys (system) Pilote de la classe Clavier: System32\DRIVERS\kbdclass.sys (system) Mélangeur audio Wave de noyau Microsoft: system32\drivers\kmixer.sys (manual start) Serveur: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Station de travail: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Assistance TCP/IP NetBIOS: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) mdmxsdk: System32\DRIVERS\mdmxsdk.sys (autostart) Affichage des messages: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Partage de Bureau à distance NetMeeting: C:\WINDOWS\System32\mnmsrvc.exe (manual start) Périphérique de filtrage de flux Unimodem: system32\drivers\MODEMCSA.sys (manual start) Pilote de la classe Souris: System32\DRIVERS\mouclass.sys (system) Pilote HID de souris: System32\DRIVERS\mouhid.sys (manual start) Redirecteur client WebDav: System32\DRIVERS\mrxdav.sys (manual start) MRXSMB: System32\DRIVERS\mrxsmb.sys (system) Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start) Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start) Proxy de service de répartition Microsoft: system32\drivers\MSKSSRV.sys (manual start) Proxy d'horloge de répartition Microsoft: system32\drivers\MSPCLOCK.sys (manual start) Proxy de gestion de qualité de répartition Microsoft: system32\drivers\MSPQM.sys (manual start) Pilote BIOS de gestion de systèmes Microsoft: System32\DRIVERS\mssmbios.sys (manual start) Convertisseur en T/site-à-site de répartition Microsoft: system32\drivers\MSTEE.sys (manual start) ATI WDM Specialized MVD Codec: System32\DRIVERS\atinmdxx.sys (autostart) Codec NABTS/FEC VBI: System32\DRIVERS\NABTSFEC.sys (manual start) Service Norton AntiVirus Auto-Protect: "C:\Program Files\Norton AntiVirus\navapsvc.exe" (autostart) NAVENG: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20040726.052\NAVENG.Sys (manual start) NAVEX15: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20040726.052\NavEx15.Sys (manual start) Connection TV/vidéo Microsoft: System32\DRIVERS\NdisIP.sys (manual start) Pilote TAPI NDIS d'accès distant: System32\DRIVERS\ndistapi.sys (manual start) NDIS mode utilisateur E/S Protocole: System32\DRIVERS\ndisuio.sys (manual start) Pilote réseau étendu NDIS d'accès distant: System32\DRIVERS\ndiswan.sys (manual start) Interface NetBIOS: System32\DRIVERS\netbios.sys (system) NetBT: System32\DRIVERS\netbt.sys (system) DDE réseau: %SystemRoot%\system32\netdde.exe (disabled) DSDM DDE réseau: %SystemRoot%\system32\netdde.exe (disabled) Ouverture de session réseau: %SystemRoot%\System32\lsass.exe (manual start) Connexions réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote réseau 1394: System32\DRIVERS\nic1394.sys (manual start) NLA (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Norton Unerase Protection Driver: \??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS (manual start) Norton Unerase Protection: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE (autostart) Fournisseur de la prise en charge de sécurité LM NT: %SystemRoot%\System32\lsass.exe (manual start) Stockage amovible: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) NTSIM: \??\C:\WINDOWS\System32\ntsim.sys (manual start) Pilote de filtre de trafic IPX: System32\DRIVERS\nwlnkflt.sys (manual start) Pilote de transfert de trafic IPX: System32\DRIVERS\nwlnkfwd.sys (manual start) Contrôleur hôte compatible IEE 1394 VIA OHCI: System32\DRIVERS\ohci1394.sys (system) Pilote de port parallèle: System32\DRIVERS\parport.sys (manual start) PCI Bus Driver: System32\DRIVERS\pci.sys (system) PADUS ASPI SHELL: system32\drivers\pfc.sys (manual start) Plug-and-Play: %SystemRoot%\system32\services.exe (autostart) Services IPSEC: %SystemRoot%\System32\lsass.exe (autostart) Miniport réseau étendu (PPTP): System32\DRIVERS\raspptp.sys (manual start) Pilote processeur: System32\DRIVERS\processr.sys (system) Emplacement protégé: %SystemRoot%\system32\lsass.exe (autostart) Planificateur de paquets QoS: System32\DRIVERS\psched.sys (manual start) Pilote de liaison parallèle directe: System32\DRIVERS\ptilink.sys (manual start) PxHelp20: System32\DRIVERS\PxHelp20.sys (system) Logitech QuickCam Express: System32\DRIVERS\LVCM.sys (manual start) Pilote de connexion automatique d'accès distant: System32\DRIVERS\rasacd.sys (system) Gestionnaire de connexion automatique d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Miniport réseau étendu (L2TP): System32\DRIVERS\rasl2tp.sys (manual start) Gestionnaire de connexions d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote PPPOE d'accès à distance: System32\DRIVERS\raspppoe.sys (manual start) Parallèle direct: System32\DRIVERS\raspti.sys (manual start) Rdbss: System32\DRIVERS\rdbss.sys (system) RDPCDD: System32\DRIVERS\RDPCDD.sys (system) Gestionnaire de session d'aide sur le Bureau à distance: C:\WINDOWS\system32\sessmgr.exe (manual start) Pilote de filtre de lecture digitale de CD audio: System32\DRIVERS\redbook.sys (system) Routage et accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Localisateur d'appels de procédure distante (RPC): %SystemRoot%\System32\locator.exe (manual start) Appel de procédure distante (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart) QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start) Gestionnaire de comptes de sécurité: %SystemRoot%\system32\lsass.exe (autostart) SAVRT: \??\C:\WINDOWS\System32\Drivers\SAVRT.SYS (manual start) SAVRTPEL: \??\C:\WINDOWS\System32\Drivers\SAVRTPEL.SYS (autostart) ScriptBlocking Service: C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart) Carte à puce: %SystemRoot%\System32\SCardSvr.exe (autostart) Planificateur de tâches: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) SCR33X USB Smart Card Reader: System32\DRIVERS\SCR33X2K.sys (manual start) SCRx31 USB Smart Card Reader: System32\DRIVERS\scrccid.sys (manual start) Secdrv: System32\DRIVERS\secdrv.sys (manual start) Connexion secondaire: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Notification d'événement système: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Pilote de filtre Serenum: System32\DRIVERS\serenum.sys (manual start) Pilote de port série: System32\DRIVERS\serial.sys (system) Olitec Comm driver0: System32\DRIVERS\serusb.sys (manual start) Lecteur de disquettes haute densité: System32\DRIVERS\sfloppy.sys (manual start) Pare-feu Windows / Partage de connexion Internet: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Détection matériel noyau: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Détrameur décalage BDA: System32\DRIVERS\SLIP.sys (manual start) Speed Disk service: C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe (autostart) Splitter audio du noyau Microsoft: system32\drivers\splitter.sys (manual start) Spouleur d'impression: %SystemRoot%\system32\spoolsv.exe (autostart) Pilote de filtre de restauration système: System32\DRIVERS\sr.sys (system) Service de restauration système: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Srv: System32\DRIVERS\srv.sys (manual start) Service de découvertes SSDP: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) Acquisition d'image Windows (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart) StreamDispatcher: System32\DRIVERS\strmdisp.sys (autostart) BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start) Pilote de bus logiciel: System32\DRIVERS\swenum.sys (manual start) Synthétiseur de table de sons GC noyau Microsoft: system32\drivers\swmidi.sys (manual start) MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{BEB3543D-4A25-414C-96A4-289006AE7D1E} (manual start) SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start) SYMREDRV: \??\C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (manual start) SYMTDI: \??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS (autostart) Périphérique audio système du noyau Microsoft: system32\drivers\sysaudio.sys (manual start) 32bit system bus driver: \??\C:\WINDOWS\system32\drivers\sysbus32.sys (autostart) Journaux et alertes de performance: %SystemRoot%\system32\smlogsvc.exe (manual start) Téléphonie: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Pilote du protocole TCP/IP: System32\DRIVERS\tcpip.sys (system) Pilote de périphérique terminal: System32\DRIVERS\termdd.sys (system) Services Terminal Server: %SystemRoot%\System32\svchost -k DComLaunch (manual start) Thèmes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Client de suivi de lien distribué: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) ATI WDM Teletext Decoder: System32\DRIVERS\ATINTTXX.sys (autostart) Pilote de mise à jour microcode: System32\DRIVERS\update.sys (manual start) Hôte de périphérique universel Plug-and-Play: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) Onduleur: %SystemRoot%\System32\ups.exe (manual start) Pilote USB audio (WDM): system32\drivers\usbaudio.sys (manual start) Pilote parent générique USB Microsoft: System32\DRIVERS\usbccgp.sys (manual start) Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft: System32\DRIVERS\usbehci.sys (manual start) Pilote de concentrateur standard USB Microsoft: System32\DRIVERS\usbhub.sys (manual start) Pilote de scanneur USB: System32\DRIVERS\usbscan.sys (manual start) Pilote de stockage de masse USB: System32\DRIVERS\USBSTOR.SYS (manual start) Pilote miniport de contrôleur hôte universel USB Microsoft: System32\DRIVERS\usbuhci.sys (manual start) Carte vidéo VGA.: \SystemRoot\System32\drivers\vga.sys (system) VIA AGP Filter: System32\DRIVERS\viaagp1.sys (system) ViaIde: System32\DRIVERS\viaide.sys (system) vsdatant: System32\vsdatant.sys (system) TrueVector Internet Monitor: C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (autostart) Cliché instantané de volume: %SystemRoot%\System32\vssvc.exe (manual start) Horloge Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) ASUS 802.11b/g Driver for Windows XP: System32\DRIVERS\mrv8k51.sys (manual start) Pilote ARP IP d'accès distant: System32\DRIVERS\wanarp.sys (manual start) WAN Miniport (ATW): System32\DRIVERS\wanatw4.sys (manual start) Windows CE USB Serial Host Driver: system32\DRIVERS\wceusbsh.sys (manual start) Pilote WINMM de compatibilité audio WDM Microsoft: system32\drivers\wdmaud.sys (manual start) WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) winachsf: System32\DRIVERS\HSF_CNXT.sys (manual start) Infrastructure de gestion Windows: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Service de numéro de série du lecteur multimédia portable: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Carte de performance WMI: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start) Centre de sécurité: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Codec Teletext standard: System32\DRIVERS\WSTCODEC.SYS (manual start) Mises à jour automatiques: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Configuration automatique sans fil: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Service d'approvisionnement réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: *Registry value not found* -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *No values found* -------------------------------------------------- End of report, 39 055 bytes Report generated in 0,078 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
  17. Ca se manifeste par des "bulles" intempestives m'indiquant que le pC est infecté et voulant m'installer des antispywares.... La bulle "your computer is infected" revient toutes les 10 secondes même en mode sans échec. Rien de suspect dans la liste des programmes... Voici le rapport suite au choix 2 en mode sans échec (mais il n'a pas l'air d'être passionnant !) : SmitFraudFix v2.15 Rapport fait à 0:29:45,79 le 30/01/2006 Executé à partir de C:\Documents and Settings\Philippe\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
  18. J'ai malheureusement un second problème, encore plus sérieux : mon ordi plante dès les démarrage (enfin quelques secondes après). Bref pas le temps de faire quoi que ce soit en mode normal... J'ai la chance d'avoir un second PC avec une connexion internet, ce qui me permet d'écrire ici. Mais sur le PC infecté je ne parviens qu'à démarrer en mode sans échec. Est-ce qu'on peut faire smitfraudfix en mode sans échec ??? Voici le rapport Smitfraudfix, fait en mode sans échec : SmitFraudFix v2.15 Rapport fait à 0:20:03,31 le 30/01/2006 Executé à partir de C:\Documents and Settings\Philippe\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\ »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Philippe\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant" "{D81E2FC4-B0A2-11D3-21AC-07C04C21A18A}"="Replay for WindowsXP" »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
  19. Bonsoir, je suis confronté depuis ce matin à Spy axe. J'ai, comme beaucoup de monde sur ce site, essayer en vain mes antivirus et anti spywares... J'ai pris connaissance des conseils donnés sur ce forum et ai suvi la procédure indiquée (antivir en mode sans échec puis HijackThis). Voici ce que donne le rapport : Logfile of HijackThis v1.99.1 Scan saved at 23:56:21, on 29/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [Ashampoo PopUpBlocker] C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUpKiller.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" O4 - Startup: Moniteur Fax-Voix.lnk = C:\OLIFAXVX\MONITEUR.EXE O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: DSLMON-9Online.LNK = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddLink.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Fichiers communs\justDo\IECatcher.DLL/FlashCatcher.htm O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport\NTAddList.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\justDo\IECatcher.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://streamplug.com/StreamPlug/SP.cab O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.ofoto.fr/downloads/hmpr/HMPR_WI..._1/axhomepr.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/playe...5/Installer.exe O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z (file missing) O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\GHOSTS~2.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Merci de m'indiquer ce qu'il y a lieu de faire maintenant... Cordialement Philippe
×
×
  • Créer...