Aller au contenu

paga74

Membres
  • Compteur de contenus

    15
  • Inscription

  • Dernière visite

Autres informations

  • Mes langues
    Français

paga74's Achievements

Junior Member

Junior Member (3/12)

0

Réputation sur la communauté

  1. Bonjour, Conformément au précédent mail, je me suis fait prêter un CD de Windows XP Familial, mais lorsque je démarre avec celui-ci, en mode installation, il ne me propose pas l'option "réparation". Il propose simplement d'installer Windows XP en m'indiquant qu'un autre système d'exploitation est déjà présent sur la partition et que cela peut poser un problème. Cela provient-il du fait que le Pack2 est installé sur mon PC et que le CD qu'on m'a prété est avec le Pack1 ? Si oui y-a-t-il moyen de contourner ce problème en copiant directement à partir du dos les fichiers devant être remplacé sur ma config. Par avance merci.
  2. Bonjour à vous tous, Je reviens vers vous pour un problème de démarrage windows XP Familial. Rappel de ma config : Ordinateur Packard Bell Windows XP familial avec 4 master CD de restauration créés à l'origine. Pentium IV et 1Go de RAM Symptôme : - Au lancement de la machine le message suivant apparaît et empêche le démarrage de windows "\windows\system32\config\system fichier manquant ou détérioré". - Je peux accéder aux diverses options de démarrage par F8 mais lorsque je démarre en mode sans échec, le même message d'erreur apparaît. J'ai accès également à un menu "dernière bonne config" mais message identique et le menu "console de restauration" me demande d'ouvrir une cession (?), en tapant directement sur enter je suis à nouveau bloqué. - Lorsque je boote sur le master CD n°1/4, la machine le reconnait, mais au bout de quelques instants, le message suivant apparait "rentrer le master CD n°1" alors qu'il est déjà dedans. Je revalide par enter et à nouveau ce message. Merci de me transmettre des conseils pour résoudre ce problême. J'ai bien sûr des données que je souhaiterai ne pas perdre. A +
  3. Bonsoir à tous et plus particulèrement à ceux qui m'ont résolu mon problème, Pour une fois, rien à demander juste un grand remerciement pour votre disponibilité et vos conseils parfaitement adaptés au néophite que je suis. Continuez comme ça, je vous ferai de la pub. A plus et de préférence dans une autre rubrique du site.
  4. Bonsoir Régis56, J'ai pu désinstaller Dynamic Toolbar à partir d'un fichier désinstallateur qui se trouvait dans le répertoire C:\Program Files\Dynamic Toolbar\ et non pas à partir du menu "ajout-supression de programmes" où il n'apparaissait pas. Après j'ai appliqué EasyCleaner comme demandé. Avec la fonction "Registre" tout va bien, mais avec la fonction "Inutiles" j'ai des fichiers que je ne peux pas effacer. C:\Documents and Settings\PC Perso\Local Settings\Temporary Internet Files\Content.IE5 C:\Documents and Settings\PC Perso\Local Settings\Temporary Internet Files\Content.IE5\index.dat C:\Documents and Settings\PC Perso\Local Settings\~DF9463.tmp Le message d'EasyCleaner lorsque je veux supprimer ces fichiers est "Echec d'EaysyCleaner à la suppression de 3 des fichiers sélectionnés. Peut-être en cours d'utilisation." Ci-après rapport de Panda Activscan : Incident Statut Analyse Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix\Process.exe Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[2].txt Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\PC Perso\Mes documents\02 Logiciels Téléchargés\12 SmitfraudFix\SmitfraudFix.zip[smitfraudFix/Process.exe] Apparemment plus rien d'inquiétant En attendant ton avis A plus !
  5. Bonjour à tous les experts de Zebulon, Merci encore de votre aide, j'ai l'impression qu'on en voit enfin le bout ci-joints derniers rapports HouseCall, TrendMicro avec seulement des cookies et dernier rapport HijackThis. J'ai relancé un rapport PANDA Activscan dont je vous transmetttrais le résultat dès que je l'aurai. Rapport HouseCall Cookies http COOKIE_SE.5267 Rapport Trend Micro Summary of Privacy Threats: 1 item(s) classified as Tracking Cookie 3 item(s) classified as Browser Helper Cookie_Profiling (1 item) Internet Explorer Cache\estat.com Adware_2020Search (3 items) C:\Program Files\Dynamic Toolbar\ C:\Program Files\Dynamic Toolbar\Cache\home.bmp C:\Program Files\Dynamic Toolbar\PBFRV2\Cache\home.bmp Logfile of HijackThis v1.99.1 Scan saved at 17:48:16, on 24/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mageos.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe Merci encore A plus
  6. Bonsoir Régis56, Suite à ton message, tu trouveras ci-après résultat des 2 tests concernant ma machine : Résultat test House Call Scanning and Cleaning Complete HouseCall did not find any potential threats on your computer. Make sure you run HouseCall once a week to keep your PC clean and malware free. Résultat test TrendMicro Summary of Privacy Threats: 2 item(s) classified as Adware 10 item(s) classified as Tracking Cookie 4 item(s) classified as Browser Helper 21 item(s) classified as Worm Cookie_Profiling (2 items) Internet Explorer Cache\adtech.de Internet Explorer Cache\estat.com Cookie_Advertising (1 item) Internet Explorer Cache\advertising.com Cookie_Apmebf (1 item) Internet Explorer Cache\ apmebf.com Cookie_BlueStreak (1 item) Internet Explorer Cache\bluestreak.com Cookie_Com (1 item) Internet Explorer Cache\com.com Cookie_DoubleClick (1 item) Internet Explorer Cache\doubleclick.net Cookie_Hitbox (1 item) Internet Explorer Cache\hitbox.com Cookie_Mediaplex (1 item) Internet Explorer Cache\mediaplex.com Cookie_SmartAdServer (1 item) Internet Explorer Cache\www.smartadserver.com Adware_iMesh (23 items) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iMesh HKLM\SOFTWARE\Classes\Interface\{0BE385A3-85A5-4722-B677-68DAE891FF21} HKLM\SOFTWARE\Classes\Interface\{272C0D60-0561-4C83-B3DB-EB0A71F9D2EB} HKLM\SOFTWARE\Classes\Interface\{284477E4-A7CB-4055-9E1B-0EA7CBA28945} HKLM\SOFTWARE\Classes\Interface\{70CA4938-6A0F-4641-A9A9-C936E4C1E7DE} HKLM\SOFTWARE\Classes\Interface\{7468213E-010E-4EC6-A17D-642E909BA7EC} HKLM\SOFTWARE\Classes\Interface\{B86F4810-19A9-4050-9AC9-B5CF60B5799A} HKLM\SOFTWARE\Classes\Interface\{BB5B7E14-F8B4-4365-A24D-F4965C33E1EE} HKLM\SOFTWARE\Classes\Interface\{C13D4627-02F5-4B03-897A-BF6A90022DD2} HKLM\SOFTWARE\Classes\Interface\{C636F1FC-6AE4-4E6A-90AB-6D61D821A0DD} HKLM\SOFTWARE\Classes\Interface\{CB971AC0-6408-40DA-A540-92F9F256F51F} HKLM\SOFTWARE\Classes\Interface\{D5694DFE-43B6-4E05-AA29-8C556C968973} HKLM\SOFTWARE\Classes\Interface\{E2032EC2-A9AC-4ED7-9BDB-EBECACF076F2} HKLM\SOFTWARE\Classes\Interface\{EBAB4A71-8C34-461A-B57D-DD041D439555} HKLM\SOFTWARE\Classes\Interface\{F06FEA43-0CC3-4BF6-A85B-5EFB1C07AA4B} HKLM\SOFTWARE\Classes\Interface\{FC94A0F7-9C7C-4AE2-9106-5C212332B209} HKLM\S-1-5-21-4105924178-3733752182-2522596281-1006\Software\iMeshHKLM\ HKLM\SOFTWARE\Classes\Interface\{D5E7424B-5AAD-41C5-944A-077CF49F9D45} HKLM\SOFTWARE\Classes\Interface\{BE45F056-E005-437B-BE88-23ACF70B0B6A} HKLM\SOFTWARE\Classes\Interface\{A916AF3C-976D-4358-8736-95BEA0B5FD2C} HKLM\SOFTWARE\Classes\TypeLib\{C8791281-D7A4-440D-A0F8-C02E2085A21D} HKLM\SOFTWARE\Classes\GnucCOM.Core HKLM\SOFTWARE\Classes\CLSID\{42AB8D08-F741-4166-8A0D-3C1A50B43F93}\InProcServer32 Adware_BHOT_ImyonBar (1 item) HKU\S-1-5-21-4105924178-3733752182-2522596281-1006\Software\Dynamic Toolbar Adware_2020Search (3 items) C:\Program Files\Dynamic Toolbar\ C:\Program Files\Dynamic Toolbar\Cache\home.bmp C:\Program Files\Dynamic Toolbar\PBFRV2\Cache\home.bmp A plus !
  7. Bonjour Régis56, Complément à mon message de ce matin, j'ai fini la procédure malgré l'erreur de EasyCleaner que je rappelle ci-après. En fin de message se trouvent les différents rapports. J'ai appliqué le début de ta procédure mais j'ai des problèmes avec EasyCleaner. Avec la fonction "Registre" tout va bien, mais avec la fonction "Inutiles" j'ai des fichiers que je ne peux pas effacer. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat Si je relance la fonction "Inutiles" un 3ème fichier apparaît : C:\Documents and Settings\Administrateur\Local Settings\Temp\Perflib_Perfdata_7fc.dat (les 3 derniers caractères de ce fichier 7fc ne sont pas constants) Le message de EasyCleaner lorsque je veux effacer ces fichiers est : "Echec d'EasyCleaner à la suppression de 3 des fichiers sélectionnés. Peut-être en cours d'utilisation" J'ai essayé d'aller supprimer directement dans les dossiers concernés ces fichiers mais les dossiers sont vides malgré le paramétrage d'accès à tous les fichiers. Par contre si je rentre dans ces dossiers sur ma cession personnel je trouve le même type d'élément. Par ailleurs, dans le dossier c:\WINDOWS\Temp\ je trouve un fichier "Perflib_Perfdata_c34.dat" Est-ce que je peux mettre à la poubelle et détruire sans risque tous les fichiers y compris les fichiers non visibles (tels les desktop.ini) se trouvant dans des dossiers "Temp" que ce soit sous "WINDOWS" sous "ma cession personnelle" ou sous la session "Administrateur". --------------------------------------------------------- ewido anti-malware - Rapport de scan --------------------------------------------------------- + Créé le: 11:31:19, 23/04/2006 + Somme de contrôle: CA1786D8 + Résultats du scan: C:\Documents and Settings\PC Perso\Cookies\pc perso@advertising[1].txt -> TrackingCookie.Advertising : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@ehg-neuftelecom.hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@estat[1].txt -> TrackingCookie.Estat : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder ::Fin du rapport Logfile of HijackThis v1.99.1 Scan saved at 17:11:59, on 23/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mageos.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe Panda activscan Incident Statut Analyse Spyware:spyware/searchcentrix No Désinfecté Registre Windows Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@advertising[1].txt Spyware:Cookie/Hitbox No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[1].txt Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[2].txt Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@xiti[1].txt Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix\Process.exe Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@advertising[1].txt Spyware:Cookie/Hitbox No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[1].txt Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[2].txt Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\PC Perso\Cookies\pc perso@xiti[1].txt Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\PC Perso\Mes documents\02 Logiciels Téléchargés\12 SmitfraudFix\SmitfraudFix.zip[Process.exe] A plus
  8. Bonjour Régis56, J'ai appliqué le début de ta procédure mais j'ai des problèmes avec EasyCleaner. Avec la fonction "Registre" tout va bien, mais avec la fonction "Inutiles" j'ai des fichiers que je ne peux pas effacer. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat Si je relance la fonction "Inutiles" un 3ème fichier apparaît : C:\Documents and Settings\Administrateur\Local Settings\Temp\Perflib_Perfdata_7fc.dat (les 3 derniers caractères de ce fichier 7fc ne sont pas constants) Le message de EasyCleaner lorsque je veux effacer ces fichiers est : "Echec d'EasyCleaner à la suppression de 3 des fichiers sélectionnés. Peut-être en cours d'utilisation" J'ai essayé d'aller supprimer directement dans les dossiers concernés ces fichiers mais les dossiers sont vides malgré le paramétrage d'accès à tous les fichiers. Par contre si je rentre dans ces dossiers sur ma cession personnel je trouve le même type d'élément. Par ailleurs, dans le dossier c:\WINDOWS\Temp\ je trouve un fichier "Perflib_Perfdata_c34.dat" Est-ce que je peux mettre à la poubelle et détruire sans risque tous les fichiers y compris les fichiers non visibles (tels les desktop.ini) se trouvant dans des dossiers "Temp" que ce soit sous "WINDOWS" sous "ma cession personnelle" ou sous la session "Administrateur". Par avance merci La procédure EWIDO est en cours de réalisation
  9. Bonsoir Regis56, Tu trouveras ci-après les derniers rapports Smitfraudfix et HijackThis. Merci de me tenir informé de tes conclusions. SmitFraudFix v2.33b Rapport fait à 23:01:51,37, 22/04/2006 Executé à partir de C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Fin Logfile of HijackThis v1.99.1 Scan saved at 23:06:56, on 22/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe Bonne soirée
  10. Bonsoir tout le monde, Suivant les instructions précedemment reçues vous trouverez ci-après dans l'ordre chronologique d'obtention le rapport Ewido, le rapport HijackThis et celui de Panda concernant ma machine. Il reste sur le rapport PANDA une liste de menaces non désinfectées. Dois-je m'en inquiéter ? --------------------------------------------------------- ewido anti-malware - Rapport de scan --------------------------------------------------------- + Créé le: 21:23:18, 22/04/2006 + Somme de contrôle: D6C75AB7 + Résultats du scan: C:\Documents and Settings\PC Perso\Cookies\pc perso@2o7[2].txt -> TrackingCookie.2o7 : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@adtech[2].txt -> TrackingCookie.Adtech : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@advertising[1].txt -> TrackingCookie.Advertising : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@ehg-neuftelecom.hitbox[1].txt -> TrackingCookie.Hitbox : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@estat[1].txt -> TrackingCookie.Estat : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[2].txt -> TrackingCookie.Hitbox : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[1].txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder C:\Documents and Settings\PC Perso\Cookies\pc perso@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder C:\Program Files\HijackThis\backups\backup-20060422-122700-998.dll -> Adware.PowerSearch : Nettoyer et sauvegarder ::Fin du rapport Logfile of HijackThis v1.99.1 Scan saved at 21:31:34, on 22/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe C:\WINDOWS\Explorer.EXE c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mageos.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe Rapport Panda Activescan (liste des menaces non désinfectées) Incident Spyware:spyware/searchcentrix Registre Windows Spyware:Cookie/Hitbox C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[2].txt Spyware:Cookie/Weborama C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[2].txt Spyware:Cookie/Xiti C:\Documents and Settings\PC Perso\Cookies\pc perso@xiti[2].txt Outil indésirable:Application/Processor C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix\Process.exe Spyware:Cookie/Hitbox C:\Documents and Settings\PC Perso\Cookies\pc perso@hitbox[2].txt Spyware:Cookie/Weborama C:\Documents and Settings\PC Perso\Cookies\pc perso@weborama[2].txt Spyware:Cookie/Xiti C:\Documents and Settings\PC Perso\Cookies\pc perso@xiti[2].txt Outil indésirable:Application/Processor C:\Documents and Settings\PC Perso\Mes documents\02 Logiciels Téléchargés \12SmitfraudFix\SmitfraudFix.zip[Process.exe] Outil indésirable:Application/RealSpy C:\WINDOWS\system32\actskn45.ocx Adware:Adware/SpywareStrike C:\WINDOWS\Temp\sa150.exe Dans l'attente de vous lire, bonne soirée à tous
  11. Bonjour à tous et notamment à Régis56 et Naheulbeuk Je renvoie ce message car j'ai vu à la fin du dernier message de Regis56 qu'il fallait utiliser "répondre" se trouvant tout en bas de la page. J'attends vos meilleurs conseils pour résoudre mon problème. J'ai suivi les indications de Naheulbeuk en refaisant l'option 2 de smitfraudfix (voir rapport ci-après). SmitFraudFix v2.33b Rapport fait à 12:18:28,92, 22/04/2006 Executé à partir de C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Fin Après, j'ai commencé à réaliser toutes les étapes de la procédures de Regis56 mais j'ai quelques soucis. Impossible de supprimer manuellement les fichiers infectieux. Les fichiers pbfrv2.dll, 2020search.dll, bjam.dll et mspphe.dll ne se trouvent pas sur mon disque dur, ni en utilisant la fonction "exécuter" ni la fonction "rechercher". Dans la suite de la procédure avec EasyCleaner avec la fonction "inutile" impossible de supprimer 2 fichiers sur 31 trouvés. Ce sont les fichiers suivants : c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat Avec la fonction "registre" d'EasyCeaner on me propose de supprimer 132 fichiers dont la liste se trouve ci-après. Dois-je le faire ? Racine Clé de Registre Modifié Valeur de chaîne Fichiers/réf. chemin HKEY_LOCAL_MACHINE Software\Microsoft\COM3\Setup 16/08/2004 16:05:46 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\MSDTC\Setup 24/02/2006 15:15:11 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\Transaction Server\Setup(OCM) 16/08/2004 16:05:46 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\HDRegApp.exe 24/02/2006 15:09:43 c:\Apps\HDRegApp.exe HKEY_LOCAL_MACHINE Software\Adobe\Acrobat Reader\7.0\Installer\{AC76BA86-7AD7-1036-7B44-A70000000000} 24/02/2006 15:03:57 SourceDir C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\68AB67CA7DA76301B7447A0000000000\SourceList\Net 24/02/2006 15:04:03 1 C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA76301B7447A0000000000\InstallProperties 24/02/2006 15:04:03 InstallSource C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1036-7B44-A70000000000} 24/02/2006 15:04:03 InstallSource C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\4757561245DB2A844905BE302B7CCF92\SourceList\Net 24/02/2006 15:05:59 1 C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4757561245DB2A844905BE302B7CCF92\InstallProperties 24/02/2006 15:05:59 InstallSource C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{21657574-BD54-48A2-9450-EB03B2C7FC29} 24/02/2006 15:05:59 InstallSource C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 15:09:43 InstallSource C:\CABS\NIS HKEY_LOCAL_MACHINE Software\Symantec\Norton AntiVirus 22/04/2006 09:51:45 AdvChkPath C:\CABS\NIS\AdvTools\SETUP.EXE HKEY_LOCAL_MACHINE Software\Symantec\Norton AntiVirus 22/04/2006 09:51:45 AdvChkISSPath C:\CABS\NIS\AdvTools\SETUP.ISS HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\9399EE5EF9522ED40832C5941EA6F434\SourceList\Net 24/02/2006 15:00:08 1 C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\FC6B5F6CC906E82478F6AC3871C620B1\SourceList\Net 24/02/2006 15:00:38 1 C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9399EE5EF9522ED40832C5941EA6F434\InstallProperties 24/02/2006 15:00:08 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FC6B5F6CC906E82478F6AC3871C620B1\InstallProperties 24/02/2006 15:00:37 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{C6F5B6CF-609C-428E-876F-CA83176C021B} 24/02/2006 15:00:37 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5EE9939-259F-4DE2-8023-5C49E16A4F43} 24/02/2006 15:00:08 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\06E9C39A6B92ad94AB127FA06CAAED02\SourceList\Net 24/02/2006 14:59:21 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\1E995D9C86B6f1a4A8F41ABD34D31BFB\SourceList\Net 24/02/2006 14:58:55 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\41858184422Aa74418AD17DB0285E0B1\SourceList\Net 24/02/2006 14:58:49 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\6350C2CFC3850c6448A426ECAC0EF122\SourceList\Net 24/02/2006 14:58:51 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\687A92B33085e9e4B98503415A4B5E91\SourceList\Net 24/02/2006 14:59:34 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\9E9B2E211B50d7040BDF5B3F05351552\SourceList\Net 24/02/2006 14:59:13 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\CD5DA6254CFCa2f448248CC49CD1C6F7\SourceList\Net 24/02/2006 14:58:53 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\D36577651BC0f584E9815C203560BBF3\SourceList\Net 24/02/2006 14:58:59 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\E9A3F9443099d0a42A908030D0549A53\SourceList\Net 24/02/2006 14:59:30 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\06E9C39A6B92ad94AB127FA06CAAED02\InstallProperties 24/02/2006 14:59:20 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1E995D9C86B6f1a4A8F41ABD34D31BFB\InstallProperties 24/02/2006 14:58:55 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\41858184422Aa74418AD17DB0285E0B1\InstallProperties 24/02/2006 14:58:49 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6350C2CFC3850c6448A426ECAC0EF122\InstallProperties 24/02/2006 14:58:51 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\687A92B33085e9e4B98503415A4B5E91\InstallProperties 24/02/2006 14:59:34 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9E9B2E211B50d7040BDF5B3F05351552\InstallProperties 24/02/2006 14:59:12 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CD5DA6254CFCa2f448248CC49CD1C6F7\InstallProperties 24/02/2006 14:58:53 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D36577651BC0f584E9815C203560BBF3\InstallProperties 24/02/2006 14:58:59 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E9A3F9443099d0a42A908030D0549A53\InstallProperties 24/02/2006 14:59:29 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{12E2B9E9-05B1-407d-B0FD-B5F350535125} 24/02/2006 14:59:12 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{3B29A786-5803-4e9e-9B58-3014A5B4E519} 24/02/2006 14:59:34 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{449F3A9E-9903-4a0d-A209-08030D45A935} 24/02/2006 14:59:29 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{48185814-A224-447a-81DA-71BD20580E1B} 24/02/2006 14:58:49 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F} 24/02/2006 14:58:53 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{5677563D-0CB1-485f-9E18-C5025306BB3F} 24/02/2006 14:58:59 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 14:59:20 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF} 24/02/2006 14:58:55 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC2C0536-583C-46c0-844A-62CECAE01F22} 24/02/2006 14:58:51 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\806763CD7A467FB4294FB8AA52AB20BD\SourceList\Net 24/02/2006 14:58:09 1 C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\806763CD7A467FB4294FB8AA52AB20BD\InstallProperties 24/02/2006 14:58:08 InstallSource C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{DC367608-64A7-4BF7-92F4-8BAA25BA02DB} 24/02/2006 14:58:08 InstallSource C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\164AFE3E38BEB3C4C974C2D1850A5155\SourceList\Net 24/02/2006 14:59:43 1 C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\164AFE3E38BEB3C4C974C2D1850A5155\InstallProperties 24/02/2006 14:59:43 InstallSource C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E3EFA461-EB83-4C3B-9C47-2C1D58A01555} 24/02/2006 14:59:43 InstallSource C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\A78580CF10F4881418F95F8508209271\SourceList\Net 24/02/2006 14:59:48 1 C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\ACDF24ADA5C7FE34A950CC1E84DA9F91\SourceList\Net 24/02/2006 14:59:54 1 C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A78580CF10F4881418F95F8508209271\InstallProperties 24/02/2006 14:59:48 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ACDF24ADA5C7FE34A950CC1E84DA9F91\InstallProperties 24/02/2006 14:59:54 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919} 24/02/2006 14:59:54 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC08587A-4F01-4188-819F-F55880022917} 24/02/2006 14:59:48 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\55716C7B84BD300449F8D343BDE8FA96\SourceList\Net 24/02/2006 14:57:38 1 C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\55716C7B84BD300449F8D343BDE8FA96\InstallProperties 24/02/2006 14:57:38 InstallSource C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{B7C61755-DB48-4003-948F-3D34DB8EAF69} 24/02/2006 14:57:38 InstallSource C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\87627777F71810443910DED1108AAD65\SourceList\Net 24/02/2006 15:00:14 1 C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties 24/02/2006 15:00:14 InstallSource C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56} 24/02/2006 15:00:14 InstallSource C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\20B58AD20C31D6E4A967226E3BDDC02B\SourceList\Net 24/02/2006 14:58:25 1 C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\20B58AD20C31D6E4A967226E3BDDC02B\InstallProperties 24/02/2006 14:58:25 InstallSource C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2} 24/02/2006 14:58:25 InstallSource C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\1A9AF58E142C896498B3DD9905B9D80B\SourceList\Net 24/02/2006 14:59:41 1 C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\5A60346F23C4bb141B3535895672AF4B\SourceList\Net 24/02/2006 15:00:17 1 C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1A9AF58E142C896498B3DD9905B9D80B\InstallProperties 24/02/2006 14:59:41 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5A60346F23C4bb141B3535895672AF4B\InstallProperties 24/02/2006 15:00:17 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E85FA9A1-C241-4698-893B-DD99509B8DB0} 24/02/2006 14:59:41 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{F64306A5-4C32-41bb-B153-53986527FAB4} 24/02/2006 15:00:17 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 15:09:43 InstallFileName C:\CABS\NIS\SymSetup.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Microsoft Interactive Training 24/02/2006 15:09:43 MediaPath C:\cabs\SBSI\content\ HKEY_CURRENT_USER Software\Microsoft\Installer\Products\42A6D1D74D56C4548851F4805AFF1FC2\SourceList\Net 22/04/2006 10:15:25 1 C:\CABS\SHOCKFLA\ HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Installer\Products\42A6D1D74D56C4548851F4805AFF1FC2\SourceList\Net 22/04/2006 10:15:25 1 C:\CABS\SHOCKFLA\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{7D1D6A24-65D4-454C-8815-4F08A5FFF12C} 24/02/2006 14:56:43 InstallSource C:\CABS\SHOCKFLA\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\45E1A0ACF0EC66340BC98AB716CD6533\SourceList\Net 13/03/2006 08:00:26 1 C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45E1A0ACF0EC66340BC98AB716CD6533\InstallProperties 13/03/2006 08:00:25 InstallSource C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{CA0A1E54-CE0F-4366-B09C-A87B61DC5633} 13/03/2006 08:00:25 InstallSource C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D} 22/04/2006 10:07:35 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\bye25.tmp\Disk1\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\104C2FB8EC20D424CB62C6F4F94B646B\SourceList\Net 19/03/2006 10:12:47 1 C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\3BF9C8C3FDF54B043B41AE7D2227C867\SourceList\Net 19/03/2006 10:12:40 1 C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\104C2FB8EC20D424CB62C6F4F94B646B\InstallProperties 19/03/2006 10:12:47 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3BF9C8C3FDF54B043B41AE7D2227C867\InstallProperties 19/03/2006 10:12:40 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4105924178-3733752182-2522596281-1006\Products\2367501907ACC3146B82D2C3BDBB09B6\InstallProperties 19/03/2006 10:12:53 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4105924178-3733752182-2522596281-1006\Products\AE36A588B2834DD47A554108B958756D\InstallProperties 19/03/2006 10:12:49 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{3C8C9FB3-5FDF-40B4-B314-EAD722728C76} 19/03/2006 10:12:40 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{885A63EA-382B-4DD4-A755-14809B8557D6} 19/03/2006 10:12:49 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6} 19/03/2006 10:12:47 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{91057632-CA70-413C-B628-2D3CDBBB906B} 19/03/2006 10:12:53 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\3574AFE896173CC42AB8A061348B3AB9\SourceList\Net 24/02/2006 14:48:03 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\7FCDE114D557E4147AB4D3DC56385F98\SourceList\Net 24/02/2006 14:47:34 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{0A32C786-85DE-48F8-9E54-848B3E34A90C} 24/02/2006 15:09:43 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\bye177.tmp\Disk1\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\243493A986A4ABE4586A555B954F7E00\SourceList\Net 24/02/2006 14:47:07 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\SourceList\Net 24/02/2006 14:46:43 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\243493A986A4ABE4586A555B954F7E00\InstallProperties 24/02/2006 14:47:07 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\InstallProperties 24/02/2006 14:48:03 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{9A394342-4A68-4EBA-85A6-55B559F4E700} 24/02/2006 14:47:07 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} 24/02/2006 14:48:03 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CC09D895-51EF-11D2-BA2A-00A024BF101B}\1.0\HELPDIR 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\ HKEY_LOCAL_MACHINE Software\Classes\CLSID\{63CCB35F-4B6C-11D2-BA18-00A024BF101B}\InprocServer32 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CC09D895-51EF-11D2-BA2A-00A024BF101B}\1.0\0\win32 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll HKEY_LOCAL_MACHINE Software\Classes\CLSID\{629CACAE-B028-11D2-BA9E-00A024BF101B}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\OPPRIN~1\OPPRIN~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{6F367ED8-67E4-11D2-A24A-0060979C8AB8}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{6F367EDB-67E4-11D2-A24A-0060979C8AB8}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{860F3E90-4E7A-11D5-886A-00105A5B9D8F}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Factory\State 24/02/2006 15:10:29 WinBOM C:\sysprep\WINBOM.INI HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Help 18/03/2006 15:38:45 en.hlp C:\WINDOWS\ime\Shared\imepad HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders 22/04/2006 10:18:31 Folder C:\WINDOWS\msdownld.tmp|?:\msdownld.tmp HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE 24/02/2006 15:09:43 C:\WINDOWS\ORUN32.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Setup 12/04/2006 07:29:41 ServicePackCachePath c:\windows\ServicePackFiles\ServicePackCache HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus 13/03/2006 07:53:20 CurrentCacheFile C:\WINDOWS\SoftwareDistribution\EventCache\{20F56415-BB5E-42A3-A5A4-F29C0FDF12F8}.bin HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU 13/03/2006 07:53:26 CurrentCacheFile C:\WINDOWS\SoftwareDistribution\EventCache\{BBC27DFD-D10C-475E-A0CA-604EF8544D00}.bin HKEY_CURRENT_USER Software\Microsoft\Internet Explorer\Main 22/04/2006 10:15:25 Local Page C:\WINDOWS\system32\blank.htm HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Internet Explorer\Main 22/04/2006 10:15:25 Local Page C:\WINDOWS\system32\blank.htm HKEY_LOCAL_MACHINE Software\Microsoft\Internet Explorer\Main 22/04/2006 06:08:55 Local Page C:\windows\system32\blank.htm HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe 16/08/2004 16:02:19 C:\WINDOWS\system32\cmmgr32.exe HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS 24/02/2006 15:09:43 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD 13/03/2006 14:03:29 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS 13/03/2006 14:03:29 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Classes\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32 16/08/2004 16:08:03 C:\WINDOWS\system32\plugin.ocx HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32 16/08/2004 16:08:03 C:\WINDOWS\system32\plugin.ocx HKEY_LOCAL_MACHINE Software\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\SystemCookiesPath 24/02/2006 15:39:10 C:\WINDOWS\system32\syscookies.txt HKEY_LOCAL_MACHINE Software\Classes\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32 16/08/2004 16:08:17 SystemDB C:\WINDOWS\system32\system.mdw HKEY_LOCAL_MACHINE Software\Microsoft\Windows Media Device Manager 24/02/2006 15:27:56 Log.Filename C:\WINDOWS\system32\Wmdm.log HKEY_CURRENT_USER Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 a c:\windows\system32\\1 HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 a c:\windows\system32\\1 HKEY_CURRENT_USER Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 b c:\windows\system\\1 HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 b c:\windows\system\\1 A plus dans l'attente de vos prochains conseils
  12. Bonjour à tous et notamment à Régis56 et Naheulbeuk J'ai suivi les indications de Naheulbeuk en refaisant l'option 2 de smitfraudfix (voir rapport ci-après). SmitFraudFix v2.33b Rapport fait à 12:18:28,92, 22/04/2006 Executé à partir de C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Fin Après, j'ai commencé à réaliser toutes les étapes de la procédures de Regis56 mais j'ai quelques soucis. Impossible de supprimer manuellement les fichiers infectieux. Les fichiers pbfrv2.dll, 2020search.dll, bjam.dll et mspphe.dll ne se trouvent pas sur mon disque dur, ni en utilisant la fonction "exécuter" ni la fonction "rechercher". Dans la suite de la procédure avec EasyCleaner avec la fonction "inutile" impossible de supprimer 2 fichiers sur 31 trouvés. Ce sont les fichiers suivants : c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 c:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat Avec la fonction "registre" d'EasyCeaner on me propose de supprimer 132 fichiers dont la liste se trouve ci-après. Dois-je le faire ? Racine Clé de Registre Modifié Valeur de chaîne Fichiers/réf. chemin HKEY_LOCAL_MACHINE Software\Microsoft\COM3\Setup 16/08/2004 16:05:46 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\MSDTC\Setup 24/02/2006 15:15:11 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\Transaction Server\Setup(OCM) 16/08/2004 16:05:46 Source Path C:\$WIN_NT$.~LS HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\HDRegApp.exe 24/02/2006 15:09:43 c:\Apps\HDRegApp.exe HKEY_LOCAL_MACHINE Software\Adobe\Acrobat Reader\7.0\Installer\{AC76BA86-7AD7-1036-7B44-A70000000000} 24/02/2006 15:03:57 SourceDir C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\68AB67CA7DA76301B7447A0000000000\SourceList\Net 24/02/2006 15:04:03 1 C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA76301B7447A0000000000\InstallProperties 24/02/2006 15:04:03 InstallSource C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1036-7B44-A70000000000} 24/02/2006 15:04:03 InstallSource C:\CABS\AREAD\FRSETUP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\4757561245DB2A844905BE302B7CCF92\SourceList\Net 24/02/2006 15:05:59 1 C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4757561245DB2A844905BE302B7CCF92\InstallProperties 24/02/2006 15:05:59 InstallSource C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{21657574-BD54-48A2-9450-EB03B2C7FC29} 24/02/2006 15:05:59 InstallSource C:\CABS\MYDVD\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 15:09:43 InstallSource C:\CABS\NIS HKEY_LOCAL_MACHINE Software\Symantec\Norton AntiVirus 22/04/2006 09:51:45 AdvChkPath C:\CABS\NIS\AdvTools\SETUP.EXE HKEY_LOCAL_MACHINE Software\Symantec\Norton AntiVirus 22/04/2006 09:51:45 AdvChkISSPath C:\CABS\NIS\AdvTools\SETUP.ISS HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\9399EE5EF9522ED40832C5941EA6F434\SourceList\Net 24/02/2006 15:00:08 1 C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\FC6B5F6CC906E82478F6AC3871C620B1\SourceList\Net 24/02/2006 15:00:38 1 C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9399EE5EF9522ED40832C5941EA6F434\InstallProperties 24/02/2006 15:00:08 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FC6B5F6CC906E82478F6AC3871C620B1\InstallProperties 24/02/2006 15:00:37 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{C6F5B6CF-609C-428E-876F-CA83176C021B} 24/02/2006 15:00:37 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5EE9939-259F-4DE2-8023-5C49E16A4F43} 24/02/2006 15:00:08 InstallSource C:\CABS\NIS\NAV\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\06E9C39A6B92ad94AB127FA06CAAED02\SourceList\Net 24/02/2006 14:59:21 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\1E995D9C86B6f1a4A8F41ABD34D31BFB\SourceList\Net 24/02/2006 14:58:55 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\41858184422Aa74418AD17DB0285E0B1\SourceList\Net 24/02/2006 14:58:49 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\6350C2CFC3850c6448A426ECAC0EF122\SourceList\Net 24/02/2006 14:58:51 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\687A92B33085e9e4B98503415A4B5E91\SourceList\Net 24/02/2006 14:59:34 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\9E9B2E211B50d7040BDF5B3F05351552\SourceList\Net 24/02/2006 14:59:13 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\CD5DA6254CFCa2f448248CC49CD1C6F7\SourceList\Net 24/02/2006 14:58:53 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\D36577651BC0f584E9815C203560BBF3\SourceList\Net 24/02/2006 14:58:59 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\E9A3F9443099d0a42A908030D0549A53\SourceList\Net 24/02/2006 14:59:30 1 C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\06E9C39A6B92ad94AB127FA06CAAED02\InstallProperties 24/02/2006 14:59:20 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1E995D9C86B6f1a4A8F41ABD34D31BFB\InstallProperties 24/02/2006 14:58:55 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\41858184422Aa74418AD17DB0285E0B1\InstallProperties 24/02/2006 14:58:49 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6350C2CFC3850c6448A426ECAC0EF122\InstallProperties 24/02/2006 14:58:51 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\687A92B33085e9e4B98503415A4B5E91\InstallProperties 24/02/2006 14:59:34 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9E9B2E211B50d7040BDF5B3F05351552\InstallProperties 24/02/2006 14:59:12 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CD5DA6254CFCa2f448248CC49CD1C6F7\InstallProperties 24/02/2006 14:58:53 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D36577651BC0f584E9815C203560BBF3\InstallProperties 24/02/2006 14:58:59 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E9A3F9443099d0a42A908030D0549A53\InstallProperties 24/02/2006 14:59:29 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{12E2B9E9-05B1-407d-B0FD-B5F350535125} 24/02/2006 14:59:12 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{3B29A786-5803-4e9e-9B58-3014A5B4E519} 24/02/2006 14:59:34 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{449F3A9E-9903-4a0d-A209-08030D45A935} 24/02/2006 14:59:29 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{48185814-A224-447a-81DA-71BD20580E1B} 24/02/2006 14:58:49 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F} 24/02/2006 14:58:53 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{5677563D-0CB1-485f-9E18-C5025306BB3F} 24/02/2006 14:58:59 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 14:59:20 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF} 24/02/2006 14:58:55 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC2C0536-583C-46c0-844A-62CECAE01F22} 24/02/2006 14:58:51 InstallSource C:\CABS\NIS\Setup\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\806763CD7A467FB4294FB8AA52AB20BD\SourceList\Net 24/02/2006 14:58:09 1 C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\806763CD7A467FB4294FB8AA52AB20BD\InstallProperties 24/02/2006 14:58:08 InstallSource C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{DC367608-64A7-4BF7-92F4-8BAA25BA02DB} 24/02/2006 14:58:08 InstallSource C:\CABS\NIS\Support\ccCommon\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\164AFE3E38BEB3C4C974C2D1850A5155\SourceList\Net 24/02/2006 14:59:43 1 C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\164AFE3E38BEB3C4C974C2D1850A5155\InstallProperties 24/02/2006 14:59:43 InstallSource C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E3EFA461-EB83-4C3B-9C47-2C1D58A01555} 24/02/2006 14:59:43 InstallSource C:\CABS\NIS\Support\HelpMSI\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\A78580CF10F4881418F95F8508209271\SourceList\Net 24/02/2006 14:59:48 1 C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\ACDF24ADA5C7FE34A950CC1E84DA9F91\SourceList\Net 24/02/2006 14:59:54 1 C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A78580CF10F4881418F95F8508209271\InstallProperties 24/02/2006 14:59:48 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ACDF24ADA5C7FE34A950CC1E84DA9F91\InstallProperties 24/02/2006 14:59:54 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919} 24/02/2006 14:59:54 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{FC08587A-4F01-4188-819F-F55880022917} 24/02/2006 14:59:48 InstallSource C:\CABS\NIS\Support\Proxy\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\55716C7B84BD300449F8D343BDE8FA96\SourceList\Net 24/02/2006 14:57:38 1 C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\55716C7B84BD300449F8D343BDE8FA96\InstallProperties 24/02/2006 14:57:38 InstallSource C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{B7C61755-DB48-4003-948F-3D34DB8EAF69} 24/02/2006 14:57:38 InstallSource C:\CABS\NIS\Support\Redist\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\87627777F71810443910DED1108AAD65\SourceList\Net 24/02/2006 15:00:14 1 C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties 24/02/2006 15:00:14 InstallSource C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56} 24/02/2006 15:00:14 InstallSource C:\CABS\NIS\Support\SPBBC\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\20B58AD20C31D6E4A967226E3BDDC02B\SourceList\Net 24/02/2006 14:58:25 1 C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\20B58AD20C31D6E4A967226E3BDDC02B\InstallProperties 24/02/2006 14:58:25 InstallSource C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2} 24/02/2006 14:58:25 InstallSource C:\CABS\NIS\Support\SymNet\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\1A9AF58E142C896498B3DD9905B9D80B\SourceList\Net 24/02/2006 14:59:41 1 C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\5A60346F23C4bb141B3535895672AF4B\SourceList\Net 24/02/2006 15:00:17 1 C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1A9AF58E142C896498B3DD9905B9D80B\InstallProperties 24/02/2006 14:59:41 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5A60346F23C4bb141B3535895672AF4B\InstallProperties 24/02/2006 15:00:17 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{E85FA9A1-C241-4698-893B-DD99509B8DB0} 24/02/2006 14:59:41 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{F64306A5-4C32-41bb-B153-53986527FAB4} 24/02/2006 15:00:17 InstallSource C:\CABS\NIS\Support\SymSC\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} 24/02/2006 15:09:43 InstallFileName C:\CABS\NIS\SymSetup.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Microsoft Interactive Training 24/02/2006 15:09:43 MediaPath C:\cabs\SBSI\content\ HKEY_CURRENT_USER Software\Microsoft\Installer\Products\42A6D1D74D56C4548851F4805AFF1FC2\SourceList\Net 22/04/2006 10:15:25 1 C:\CABS\SHOCKFLA\ HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Installer\Products\42A6D1D74D56C4548851F4805AFF1FC2\SourceList\Net 22/04/2006 10:15:25 1 C:\CABS\SHOCKFLA\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{7D1D6A24-65D4-454C-8815-4F08A5FFF12C} 24/02/2006 14:56:43 InstallSource C:\CABS\SHOCKFLA\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\45E1A0ACF0EC66340BC98AB716CD6533\SourceList\Net 13/03/2006 08:00:26 1 C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45E1A0ACF0EC66340BC98AB716CD6533\InstallProperties 13/03/2006 08:00:25 InstallSource C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{CA0A1E54-CE0F-4366-B09C-A87B61DC5633} 13/03/2006 08:00:25 InstallSource C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.2_E\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D} 22/04/2006 10:07:35 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\bye25.tmp\Disk1\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\104C2FB8EC20D424CB62C6F4F94B646B\SourceList\Net 19/03/2006 10:12:47 1 C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\3BF9C8C3FDF54B043B41AE7D2227C867\SourceList\Net 19/03/2006 10:12:40 1 C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\104C2FB8EC20D424CB62C6F4F94B646B\InstallProperties 19/03/2006 10:12:47 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3BF9C8C3FDF54B043B41AE7D2227C867\InstallProperties 19/03/2006 10:12:40 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4105924178-3733752182-2522596281-1006\Products\2367501907ACC3146B82D2C3BDBB09B6\InstallProperties 19/03/2006 10:12:53 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4105924178-3733752182-2522596281-1006\Products\AE36A588B2834DD47A554108B958756D\InstallProperties 19/03/2006 10:12:49 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{3C8C9FB3-5FDF-40B4-B314-EAD722728C76} 19/03/2006 10:12:40 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{885A63EA-382B-4DD4-A755-14809B8557D6} 19/03/2006 10:12:49 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6} 19/03/2006 10:12:47 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{91057632-CA70-413C-B628-2D3CDBBB906B} 19/03/2006 10:12:53 InstallSource C:\DOCUME~1\PCPERS~1\LOCALS~1\Temp\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\3574AFE896173CC42AB8A061348B3AB9\SourceList\Net 24/02/2006 14:48:03 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\7FCDE114D557E4147AB4D3DC56385F98\SourceList\Net 24/02/2006 14:47:34 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{0A32C786-85DE-48F8-9E54-848B3E34A90C} 24/02/2006 15:09:43 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\bye177.tmp\Disk1\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\243493A986A4ABE4586A555B954F7E00\SourceList\Net 24/02/2006 14:47:07 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\SourceList\Net 24/02/2006 14:46:43 1 C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\243493A986A4ABE4586A555B954F7E00\InstallProperties 24/02/2006 14:47:07 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\InstallProperties 24/02/2006 14:48:03 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{9A394342-4A68-4EBA-85A6-55B559F4E700} 24/02/2006 14:47:07 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} 24/02/2006 14:48:03 InstallSource C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\IXP000.TMP\ HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CC09D895-51EF-11D2-BA2A-00A024BF101B}\1.0\HELPDIR 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\ HKEY_LOCAL_MACHINE Software\Classes\CLSID\{63CCB35F-4B6C-11D2-BA18-00A024BF101B}\InprocServer32 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CC09D895-51EF-11D2-BA2A-00A024BF101B}\1.0\0\win32 18/03/2006 15:46:37 C:\PROGRA~1\Canon\PhotoRecord\OpPrintCom\OpPrintCom.dll HKEY_LOCAL_MACHINE Software\Classes\CLSID\{629CACAE-B028-11D2-BA9E-00A024BF101B}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\OPPRIN~1\OPPRIN~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{6F367ED8-67E4-11D2-A24A-0060979C8AB8}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{6F367EDB-67E4-11D2-A24A-0060979C8AB8}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Classes\CLSID\{860F3E90-4E7A-11D5-886A-00105A5B9D8F}\LocalServer32 18/03/2006 15:46:39 C:\PROGRA~1\Canon\PHOTOR~1\Program\PHOTOR~1.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Factory\State 24/02/2006 15:10:29 WinBOM C:\sysprep\WINBOM.INI HKEY_LOCAL_MACHINE Software\Microsoft\Windows\Help 18/03/2006 15:38:45 en.hlp C:\WINDOWS\ime\Shared\imepad HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders 22/04/2006 10:18:31 Folder C:\WINDOWS\msdownld.tmp|?:\msdownld.tmp HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE 24/02/2006 15:09:43 C:\WINDOWS\ORUN32.EXE HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Setup 12/04/2006 07:29:41 ServicePackCachePath c:\windows\ServicePackFiles\ServicePackCache HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus 13/03/2006 07:53:20 CurrentCacheFile C:\WINDOWS\SoftwareDistribution\EventCache\{20F56415-BB5E-42A3-A5A4-F29C0FDF12F8}.bin HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU 13/03/2006 07:53:26 CurrentCacheFile C:\WINDOWS\SoftwareDistribution\EventCache\{BBC27DFD-D10C-475E-A0CA-604EF8544D00}.bin HKEY_CURRENT_USER Software\Microsoft\Internet Explorer\Main 22/04/2006 10:15:25 Local Page C:\WINDOWS\system32\blank.htm HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Internet Explorer\Main 22/04/2006 10:15:25 Local Page C:\WINDOWS\system32\blank.htm HKEY_LOCAL_MACHINE Software\Microsoft\Internet Explorer\Main 22/04/2006 06:08:55 Local Page C:\windows\system32\blank.htm HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe 16/08/2004 16:02:19 C:\WINDOWS\system32\cmmgr32.exe HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS 24/02/2006 15:09:43 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD 13/03/2006 14:03:29 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS 13/03/2006 14:03:29 RequiredFile C:\WINDOWS\system32\enable.dvd HKEY_LOCAL_MACHINE Software\Classes\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32 16/08/2004 16:08:03 C:\WINDOWS\system32\plugin.ocx HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32 16/08/2004 16:08:03 C:\WINDOWS\system32\plugin.ocx HKEY_LOCAL_MACHINE Software\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\SystemCookiesPath 24/02/2006 15:39:10 C:\WINDOWS\system32\syscookies.txt HKEY_LOCAL_MACHINE Software\Classes\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32 16/08/2004 16:08:17 SystemDB C:\WINDOWS\system32\system.mdw HKEY_LOCAL_MACHINE Software\Microsoft\Windows Media Device Manager 24/02/2006 15:27:56 Log.Filename C:\WINDOWS\system32\Wmdm.log HKEY_CURRENT_USER Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 a c:\windows\system32\\1 HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 a c:\windows\system32\\1 HKEY_CURRENT_USER Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 b c:\windows\system\\1 HKEY_USERS S-1-5-21-4105924178-3733752182-2522596281-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 22/04/2006 11:07:53 b c:\windows\system\\1 A plus dans l'attente de vos prochains conseils
  13. Bonjour tout le monde ! Merci de vos derniers conseils. Vous trouverez ci-après derniers rappports Smitfraudfix et Hijackthis. Puis-je m'être à la poubelle les 2 icones qui se trouvent sur mon bureau nommés "Online Security Guide" et "Security Troubleshooting". Concernant le matériel inconnu qui apparait dans mon gestionnaire de périphérique (voir description dans mon 1er message) puis-je le désinstaller sans risque en cliquant dessus et en utilisant la fonction "désinstaller" sous le gestionnaire de périphérique ? Logfile of HijackThis v1.99.1 Scan saved at 08:16:22, on 22/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe SmitFraudFix v2.33b Rapport fait à 8:10:54,32, 22/04/2006 Executé à partir de C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Fin Par avance Merci A plus tard.
  14. Merci "naheulbeuk" pour tes 1ères indications que j'ai suivies à la lettre. Tu trouveras ci-après le rapport HijackThis et SmitFraudFix concernant mon ordinateur. En espérant que ça te parlera. Logfile of HijackThis v1.99.1 Scan saved at 22:18:40, on 21/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redi...se=6&key=SEARCH R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mageos.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe SmitFraudFix v2.33b Rapport fait à 22:21:10,67, 21/04/2006 Executé à partir de C:\Documents and Settings\PC Perso\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\hp????.tmp PRESENT ! C:\WINDOWS\system32\ld????.tmp PRESENT ! C:\WINDOWS\system32\nvctrl.exe PRESENT ! C:\WINDOWS\system32\1024\ PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\PC Perso\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PCPERS~1\Favoris C:\DOCUME~1\PCPERS~1\Favoris\Antivirus Test Online.url PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» Bureau »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Ma page d'accueil" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" [HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" [HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin Cordialement A plus tard
  15. Bonjour, 4 éléments se sont installés ce jour sur mon ordinateur, SpywareQuake, Sudoku, Online Security Guide et Security Trouble shooting. Je pense avoir réussi à supprimer SpywareQuake et Sudoku (en utilisant le menu de désinstallation que j'ai trouvé et en supprimant tous les fichiers restant après désinstallation), par contre j'ai toujours sur mon bureau les 2 autres porgrammes. J'ai constaté par ailleurs un autre problème après l'apparition de ces virus, en redémarrant windows celui-ci a détecté un nouveau matériel et m'a proposé d'installer les pilotes ce que je n'ai pas fait. En allant dans le gestionnaire de périphérique j'ai découvert dans la famille "Autres périphériques" un périphérique nommé "Périphérique Inconnu" alors que tous mes matériels installés semblent bien fonctionner. Voici ci-après les info. trouvé dans les sous-menu : Pilote : "Aucun fichier de pilote n'est nécessaire ou n'a été chargé pour ce périphérique", on me propose également de supprimer ces pilotes Détails : Numéro d'identification de l'instance de périphérique : ROOT\LEGACY_PCAMPR5\0000 Service : PCAMPR5 Enumérateur : ROOT Indicateur Devnode : DN_ROOT_ENUMERATED DN_HAS_PROBLEM DN_DISABLEABLE DN_NT_DRIVER CSConfigFlags : CSCONFIGFLAG_DISABLED Etat actuel de l'alimentation : D3 Fonctions de gestion de l'alimentation : PDCAP_D0_SUPPORTED PDCAP_D3_SUPPORTED Mappages d'état d'alimentation : S0->D0 S1->D3 S2->D3 S3->D3 S4->D3 S5->D3 Voila l'ensemble des éléments concernant ce problème. Ci-après rapport concernant le scan de HijackThis Logfile of HijackThis v1.99.1 Scan saved at 18:28:32, on 21/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe C:\Documents and Settings\PC Perso\Mes documents\02 Logiciels Téléchargés\10 HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redi...se=6&key=SEARCH R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mageos.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mageos.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: PBFRV2 - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - C:\WINDOWS\system32\pbfrv2.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [D066UUtility] C:\WINDOWS\TWAIN_32\D66U\D066UUTY.EXE O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Alice_Triway_WiFi\Wizard\Agent_WiFi.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1142929861890 O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe Voilà ce sont l'ensemble des éléments en ma possession à cet instant, cela ressemble un peu pour moi à du chinois, merci d'avance de me faire profiter de votre expérience. A bientôt
×
×
  • Créer...